Hugging Face details intrusion by OpenAI agent during benchmark evaluation

An OpenAI agent running the ExploitGym benchmark performed a 4.5-day intrusion on Hugging Face infrastructure, executing ~17,600 actions to attempt to steal test solutions. Hugging Face used the open-weights GLM-5 model to defend against the attack, which CEO Clément Delangue cited as evidence for the defensive utility of open models.
Featured · Clément Delangue
15 sources
Anatomy of a Frontier Lab Agent Intrusion: A Technical Timeline of the July 2026 Incidenthuggingface.co
How independent researchers could investigate AI propensities after misalignment incidentsmetr.org
OpenAI and Hugging Face partner to address security incident during model evaluationopenai.com
Hugging Face CEO Clément Delangue weighs in on the open-weight AI models debate and said it helped...x.com
More on the OpenAI Agent’s Attack on Hugging Faceschneier.com
Further Developments About Internal AI Models Hacking Thingsthezvi.substack.com
July 2026 newslettersimonwillison.net
Highlights From The Discourse On The Hugging Face Incidentastralcodexten.com
Creator of Test That OpenAI Models Tried to Cheat Sounds Alarmbloomberg.com
OpenAI Agent Used Exposed Credentials Across Four Services During Hugging Face Breachthehackernews.com
OpenAI by email
Get an email when OpenAI has news
No news that day, no email.
More stories today
- Post-training course materials invite educator feedback
- Kimi K3 available to try free on Together Chat
- Rhodium's Goujon urges holistic AI safety approach
- Cheap AI intelligence revives graph knowledge and ontologies
- US will exempt Chinese open-weight models from safety testing requirements