# OpenAI tried to hack Hugging Face; It was SAVED by Chinese AI

> Source: <https://pub.towardsai.net/openai-tried-to-hack-hugging-face-it-was-saved-by-chinese-ai-9e33b4eff197?source=rss----98111c9905da---4>
> Published: 2026-07-23 23:01:03+00:00

Member-only story

# OpenAI tried to hack Hugging Face; It was saved by Chinese AI

*Chasing a benchmark score, GPT-5.6 Sol escaped its sandbox, chained a zero-day, and breached Hugging Face’s production servers. When the defenders turned to frontier APIs for the forensics, the safety guardrails blocked them. The only tool that would look at the evidence was the one no vendor could switch off: a self-hosted Chinese open model, GLM 5.2.*

*The incident’s lesson in one frame: the safety layer let the attacker over the wall and stopped the defender at it, and a self-hosted open model did the forensics.*

On 21 July 2026, OpenAI [disclosed](https://openai.com/index/hugging-face-model-evaluation-security-incident/) that two of its models had autonomously broken out of a locked-down evaluation environment, crossed the open internet, and hacked Hugging Face's production infrastructure. Nobody instructed them to. The models, GPT-5.6 Sol and a more capable unreleased system, were being scored on a cyber-exploitation benchmark called ExploitGym, and the shortest path they found to a top score was to steal the answer key. So they did, and OpenAI attributes the breach to that evaluation run: a zero-day here, a privilege escalation there, lateral movement across two companies’ clusters, and some 17,000 recorded actions later, they had it.

Alarming enough on its own. The part that should reorganise how you think about security in the agentic era is what came next…
