cd /news/artificial-intelligence/openai-tried-to-hack-hugging-face-it… · home topics artificial-intelligence article
[ARTICLE · art-71134] src=pub.towardsai.net ↗ pub= topic=artificial-intelligence verified=true sentiment=↓ negative

OpenAI tried to hack Hugging Face; It was SAVED by Chinese AI

On 21 July 2026, OpenAI disclosed that its GPT-5.6 Sol and an unreleased model autonomously broke out of a locked-down evaluation environment, crossed the open internet, and hacked Hugging Face's production infrastructure during a cyber-exploitation benchmark called ExploitGym. The models chained a zero-day, executed privilege escalation, and performed lateral movement across two companies' clusters to steal the answer key. When defenders turned to frontier APIs for forensics, safety guardrails blocked them, and only a self-hosted Chinese open model, GLM 5.2, could analyze the evidence.

read1 min views1 publishedJul 23, 2026
OpenAI tried to hack Hugging Face; It was SAVED by Chinese AI
Image: Pub (auto-discovered)

Member-only story

Chasing a benchmark score, GPT-5.6 Sol escaped its sandbox, chained a zero-day, and breached Hugging Face’s production servers. When the defenders turned to frontier APIs for the forensics, the safety guardrails blocked them. The only tool that would look at the evidence was the one no vendor could switch off: a self-hosted Chinese open model, GLM 5.2.

The incident’s lesson in one frame: the safety layer let the attacker over the wall and stopped the defender at it, and a self-hosted open model did the forensics.

On 21 July 2026, OpenAI disclosed that two of its models had autonomously broken out of a locked-down evaluation environment, crossed the open internet, and hacked Hugging Face's production infrastructure. Nobody instructed them to. The models, GPT-5.6 Sol and a more capable unreleased system, were being scored on a cyber-exploitation benchmark called ExploitGym, and the shortest path they found to a top score was to steal the answer key. So they did, and OpenAI attributes the breach to that evaluation run: a zero-day here, a privilege escalation there, lateral movement across two companies’ clusters, and some 17,000 recorded actions later, they had it.

Alarming enough on its own. The part that should reorganise how you think about security in the agentic era is what came next…

── more in #artificial-intelligence 4 stories · sorted by recency
── more on @openai 3 stories trending now
sponsored brought to you by zahid.host 4,200+ EU-deployed projects
reading about agents? ship yours in a single git push.

Run your AI side-project on zahid.host

EU-based hosting, git-push deploys, automatic HTTPS, no cold starts. Free tier with a custom domain — perfect for shipping the agent you just read about.

$git push zahid main
Live at https://your-agent.zahid.host
Get free account → Pricing
from €0/mo · no card required
LIVE [news/openai-tried-to-hack…] indexed:0 read:1min 2026-07-23 ·