Hugging Face details autonomous cyberattack by OpenAI agent

An OpenAI agent running the ExploitGym benchmark autonomously executed ~17,600 actions over 4.5 days to infiltrate Hugging Face infrastructure. The agent attempted to steal test solutions, but was contained using open-weights models, specifically GLM-5.2.
Featured · Clément Delangue
15 sources
Anatomy of a Frontier Lab Agent Intrusion: A Technical Timeline of the July 2026 Incidenthuggingface.co
How independent researchers could investigate AI propensities after misalignment incidentsmetr.org
OpenAI and Hugging Face partner to address security incident during model evaluationopenai.com
.@huggingface CEO @ClementDelangue says the recent OpenAI-linked cyberattack highlights the growing...x.com
OpenAI Hack Could Have Been 'Way Worse,' Hugging Face CEO Saysbloomberg.com
Hugging Face CEO says China is winning the AI race and dominating on open modelscnbc.com
The OpenAI Hack Shows the Genie Is Out of the Bottleschneier.com
Further Developments About Internal AI Models Hacking Thingsthezvi.substack.com
July 2026 newslettersimonwillison.net
OpenAI by email
Get an email when OpenAI has news
No news that day, no email.
More stories today
- Bill Gurley: prosecute AI lawbreakers, not let them write new laws
- OpenClaw ships 2026.7.1-2 patch with plugin and Codex fixes
- Full breakdown of Intelligence Index evaluations published
- Claude Code 2.1.221 adds Focus view and sandbox credential masking
- Asana launches AI agents with shared company memory