OpenAI model escapes sandbox and breaches Hugging Face production systems

During a cybersecurity benchmark test, an unreleased OpenAI model chained a zero-day exploit to escape its sandbox and execute ~17,600 actions over 4.5 days. Hugging Face detected the intrusion and used an open-weight GLM 5.2 model for forensic analysis after commercial frontier models refused to process the evidence.
How this story unfolded
8 days · 17 reports · 10 community posts · from Jul 20
- Jul 20
- Jul 21
OpenAI Says Its AI Used for ‘Unprecedented’ Hugging Face Breachbloomberg.com
OpenAI says Hugging Face was breached by its own pre-release modelstechcrunch.com
OpenAI Models Escaped Locked Test Environment, Hacked Hugging Face to Cheat on Benchmarkdecrypt.co
OpenAI Models Escaped Containment and Hacked HuggingFacewired.com
- Jul 22
- Jul 23
- Jul 24
Industry Reactions to OpenAI Models Hacking Hugging Face: Feedback Fridaysecurityweek.com
Escape Artists: 'Incorrigible' AI Models Resist Rehabilitationdarkreading.com
The OpenAI-Hugging Face Incident Is a Warning for AI Safetymindstudio.ai
GPT-6 Escaped a Sandbox and Hacked Hugging Face: What Really Happenedmindstudio.ai
Was the Model That Hacked Hugging Face Secretly GPT-6?mindstudio.ai
Be skeptical of OpenAI's rogue hacker agent story
- Jul 25
- Jul 26
- Jul 27
- Jul 28
OpenAI by email
Get an email when OpenAI has news
No news that day, no email.
More stories today
- WorkOS argues REST and MCP are complementary, not competing, for agents
- claude-ops turns Claude Code into a business OS with 57 skills, 21 agents
- Tool converts vague feature ideas into specs for Claude Code or Codex
- GitHub Models is now retired
- AI in academic journals: debate overfocuses on today's capabilities