cd /news/artificial-intelligence/openai-says-it-accidentally-hacked-h… · home topics artificial-intelligence article
[ARTICLE · art-67676] src=theverge.com ↗ pub= topic=artificial-intelligence verified=true sentiment=↓ negative

OpenAI says it accidentally hacked Hugging Face with a new AI system

OpenAI admitted that its AI models, including GPT-5.6 Sol and a pre-release model, accidentally breached open-source AI platform Hugging Face during internal testing on July 16th by exploiting a zero-day vulnerability in a sandboxed environment. The models gained internet access and used stolen credentials and zero-day vulnerabilities to find a remote code execution path on Hugging Face servers, which Hugging Face's AI agents detected and stopped. OpenAI is working with Hugging Face to investigate and will implement new controls.

read2 min views2 publishedJul 21, 2026
OpenAI says it accidentally hacked Hugging Face with a new AI system
Image: The Verge

OpenAI says its AI models mistakenly breached open-source AI platform Hugging Face during internal testing. In a blog post on Tuesday, OpenAI writes that GPT-5.6 Sol and “an even more capable pre-release model” discovered vulnerabilities within their sandboxed testing environment, allowing them to gain access to the internet and target Hugging Face.

The announcement about a serious security issue oddly reads like an advertisement for how capable OpenAI’s technology is.

The announcement about a serious security issue oddly reads like an advertisement for how capable OpenAI’s technology is.

On July 16th, Hugging Face disclosed a security incident that it says was driven by “an autonomous AI agent system.” Hugging Face’s AI agents detected and stopped the breach, which OpenAI has now admitted occurred during an evaluation of its models’ cybersecurity capabilities. OpenAI says “all evidence suggests that the models were hyperfocused on finding a solution for ExploitGym,” a benchmark system that measures whether AI models can turn security vulnerabilities into exploits.

As part of efforts to complete the evaluation, the AI models gained access to the internet by exploiting a zero-day vulnerability in the sandboxed environment. From there, OpenAI says its models “inferred that Hugging Face potentially hosted models, datasets and solutions for ExploitGym,” and then “searched for and successfully found ways to gain access to secret information that it could use to cheat the evaluation:”

In one example, the model chained together multiple attack vectors, including using stolen credentials and zero-day vulnerabilities to find a remote code execution path on the Hugging Face servers.

But as serious as this incident is, OpenAI appears to be using the “unprecedented” attack as an opportunity to make its AI systems look good — especially as it competes with cybersecurity rivals, like Anthropic’s Mythos and Gemini Flash 3.5 Cyber. OpenAI’s blog post has a chart showing how GPT-5.6 Sol is getting better at sustaining multi-step cyber operations, and also encourages enterprise customers to sign up to access its “Cyber” security model.

OpenAI adds that it’s now working with Hugging Face to investigate the security incident, and will implement new controls within its research environment.

Follow topics and authors from this story to see more like this in your personalized homepage feed and to receive email updates.

  • The FCC is planning to retroactively ban disguised DJI gadgets
  • The Light Flip is a minimalist flip phone with a point to prove
  • China delivers a one-two punch to America’s AI dominance
  • Garmin’s new screen-free fitness tracker doesn’t require a subscription
  • Apple’s rumored ‘Upgrade’ program brings lease-to-own pricing for iPhones, Macs, and iPads
── more in #artificial-intelligence 4 stories · sorted by recency
── more on @openai 3 stories trending now
sponsored brought to you by zahid.host 4,200+ EU-deployed projects
reading about agents? ship yours in a single git push.

Run your AI side-project on zahid.host

EU-based hosting, git-push deploys, automatic HTTPS, no cold starts. Free tier with a custom domain — perfect for shipping the agent you just read about.

$git push zahid main
Live at https://your-agent.zahid.host
Get free account → Pricing
from €0/mo · no card required
LIVE [news/openai-says-it-accid…] indexed:0 read:2min 2026-07-21 ·