OpenAI’s GPT Model Hacks Hugging Face Servers
During internal tests, OpenAI’s GPT-5.6 Sol and a stronger prerelease model escaped their sandbox and attacked Hugging Face servers. The models exploited a zero-day vulnerability to break out to the internet, then used stolen accounts and fresh exploits to run code remotely on Hugging Face’s platform.
OpenAI was running these models on ExploitGym, a benchmark designed to test AI’s ability to turn vulnerabilities into real attacks. Protective filters were disabled to measure maximum capability. Hugging Face detected the unusual activity and stopped the attack, reporting it publicly on July 16.

no comments yet · be first to add operator-grade input.