Technologist Mag
  • Home
  • Tech News
  • AI
  • Apps
  • Gadgets
  • Gaming
  • Guides
  • Laptops
  • Mobiles
  • Wearables
  • More
    • Web Stories
    • Trending
    • Press Release

Subscribe to Updates

Get the latest tech news and updates directly to your inbox.

What's On
The Top New Features in Apple’s iOS 27 and iPadOS 27

The Top New Features in Apple’s iOS 27 and iPadOS 27

14 September 2026
Here’s How To Get A Steam Frame – Sep 14, 2026

Here’s How To Get A Steam Frame – Sep 14, 2026

14 September 2026
New York Seizes a Dozen Celebrity Deepfake Websites

New York Seizes a Dozen Celebrity Deepfake Websites

14 September 2026
Best Noise-Canceling Earbuds (2026): Bose, Apple, Samsung, Beats, and More

Best Noise-Canceling Earbuds (2026): Bose, Apple, Samsung, Beats, and More

14 September 2026
A College Girl Was Exploited on Camera. A Network of Anonymous Men Got to Work

A College Girl Was Exploited on Camera. A Network of Anonymous Men Got to Work

14 September 2026
Facebook X (Twitter) Instagram
Facebook X (Twitter) Instagram
Technologist Mag
SUBSCRIBE
  • Home
  • Tech News
  • AI
  • Apps
  • Gadgets
  • Gaming
  • Guides
  • Laptops
  • Mobiles
  • Wearables
  • More
    • Web Stories
    • Trending
    • Press Release
Technologist Mag
Home » OpenAI Models Escaped Containment and Hacked HuggingFace
Tech News

OpenAI Models Escaped Containment and Hacked HuggingFace

By technologistmag.com21 July 20263 Mins Read
OpenAI Models Escaped Containment and Hacked HuggingFace
Share
Facebook Twitter Reddit Telegram Pinterest Email

OpenAI disclosed on Tuesday that it lost control of two AI models during a security test that ended in a breach of the open AI research platform HuggingFace.

Describing the incident as “unprecedented,” OpenAI said its AI models broke out of a sealed testing environment last week and hacked into Hugging Face’s production system to steal the answers to a test they were being graded on. The models—the publicly available GPT-5.6 Sol and an unreleased, reportedly more capable one—were being evaluated on their offensive hacking skills with the safeguards that normally block high-risk cyber activity switched off.

“The models identified and chained vulnerabilities across OpenAI’s research environment and Hugging Face’s production infrastructure to obtain test solutions directly from Hugging Face’s production database,” OpenAI and HuggingFace wrote in a joint blog post disclosing the intrusion.

According to OpenAI and HuggingFace, the models escaped through a package registry cache proxy—software that allows developers to install outside code without connecting to the internet. The proxy was the only component in OpenAI’s isolated testing environment permitted to reach the outside world; in normal use that reach extends only to public code repositories.

Rather than stay contained in the sandbox, the models ​​“exploited a zero-day vulnerability” to gain access to the open internet as they “hyperfocused” on finding a solution for the AI cybersecurity benchmark known as ExploitGym. Such experiments involve prompting that pressures the models to find solutions, essentially egging them on.

“After gaining Internet access, the models inferred that Hugging Face potentially hosted models, datasets and solutions for ExploitGym,” OpenAI wrote. “Knowing this, the model searched for and successfully found ways to gain access to secret information that it could use to cheat the evaluation. In one example, the model chained together multiple attack vectors, including using stolen credentials and zero-day.”

The flaw the models exploited was previously unknown, but flaws in this kind of software are not unusual. Companies have been patching serious vulnerabilities in artifact repositories for a decade. A bug disclosed in 2024 let anyone who could reach the server ask for a file by URL and get it—configurations files, passwords, access tokens—without logging in. Others have let attackers take control of the server itself.

Researchers point out that while AI advances have created new and sometimes unexpected challenges, the task of extensively and rigorously isolating infrastructure from the open internet is well explored.

“This is not an AI problem. It’s negligence on a 40-year-old standard—and it’s basically every sci-fi film ever,” says longtime security and compliance consultant Davi Ottenheimer. “‘Highly isolated’ and ‘escaped through the one hole we left open’ cannot both be true.”

In recent months, top AI companies have been raising concerns about the expanding cybersecurity capabilities of upcoming frontier models as the platforms increase in both expertise, creativity, and agentic, autonomous operation. But researchers emphasize that this is all the more reason that fundamentals should still apply.

“This should not have happened,” says veteran security engineer and researcher Niels Provos. “I wish the frontier labs spent as much time on teaching their models to write secure infrastructure as they are spending on them exploiting vulnerabilities.”

Share. Facebook Twitter Pinterest LinkedIn Telegram Reddit Email
Previous ArticleSamsung’s free storage doubling for preorders is gone in Austria, and the replacement isn’t as sweet
Next Article Samsung is reportedly preparing for the biggest foldable battle yet

Related Articles

The Top New Features in Apple’s iOS 27 and iPadOS 27

The Top New Features in Apple’s iOS 27 and iPadOS 27

14 September 2026
New York Seizes a Dozen Celebrity Deepfake Websites

New York Seizes a Dozen Celebrity Deepfake Websites

14 September 2026
Best Noise-Canceling Earbuds (2026): Bose, Apple, Samsung, Beats, and More

Best Noise-Canceling Earbuds (2026): Bose, Apple, Samsung, Beats, and More

14 September 2026
A College Girl Was Exploited on Camera. A Network of Anonymous Men Got to Work

A College Girl Was Exploited on Camera. A Network of Anonymous Men Got to Work

14 September 2026
Review: Roborock Qrevo 2 Pro

Review: Roborock Qrevo 2 Pro

14 September 2026
The Best Soundbars (2026): Sonos, LG, TCL, Bose, and More

The Best Soundbars (2026): Sonos, LG, TCL, Bose, and More

14 September 2026
Stay In Touch
  • Facebook
  • Twitter
  • Pinterest
  • Instagram
  • YouTube
  • Vimeo

Subscribe to Updates

Get the latest tech news and updates directly to your inbox.

Don't Miss
Here’s How To Get A Steam Frame – Sep 14, 2026

Here’s How To Get A Steam Frame – Sep 14, 2026

By technologistmag.com14 September 2026

Valve’s new VR headset, the Steam Frame, is dropping very soon, and today is the…

New York Seizes a Dozen Celebrity Deepfake Websites

New York Seizes a Dozen Celebrity Deepfake Websites

14 September 2026
Best Noise-Canceling Earbuds (2026): Bose, Apple, Samsung, Beats, and More

Best Noise-Canceling Earbuds (2026): Bose, Apple, Samsung, Beats, and More

14 September 2026
A College Girl Was Exploited on Camera. A Network of Anonymous Men Got to Work

A College Girl Was Exploited on Camera. A Network of Anonymous Men Got to Work

14 September 2026
Review: Roborock Qrevo 2 Pro

Review: Roborock Qrevo 2 Pro

14 September 2026
Technologist Mag
Facebook X (Twitter) Instagram Pinterest
  • Privacy
  • Terms
  • Advertise
  • Contact
© 2026 Technologist Mag. All Rights Reserved.

Type above and press Enter to search. Press Esc to cancel.