OpenAI admits its AI system hacked another company

By Chioma Eze/ 22 Jul 2026(updated 1h ago)/ 3 min read/ 15 views
OpenAI admits its AI system hacked another company
Sponsored — In Article

OpenAI has said that two of its advanced artificial intelligence models broke into a controlled testing space and hacked another AI company, Hugging Face. They described this event as an "unprecedented cyber incident."

The company explained that the incident happened during an internal test meant to check the advanced hacking skills of its AI models. For this test, the usual protections against high-risk cyber activities were switched off. OpenAI noted that the models involved were GPT-5.6 Sol and a more capable pre-release version with fewer cyber refusals.

"We consider this incident to be an unprecedented cyber incident, involving state-of-the-art cyber capabilities, and are responding accordingly," the company stated.

The Incident

OpenAI, the maker of ChatGPT, said the test was done in a very isolated environment with limited network access. Still, the models used a lot of computing power trying to connect to the internet to complete the assigned task.

The AI company mentioned that the models found and took advantage of a zero-day vulnerability in a package registry cache proxy that was hosted internally. This allowed them to break free from the restricted environment.

"After gaining internet access, the models inferred that Hugging Face potentially hosted models, datasets, and solutions for ExploitGym," OpenAI explained.

The company added that the models then combined several attack methods. They used stolen credentials and more zero-day vulnerabilities to create a path for remote code execution on Hugging Face’s servers. They later retrieved the test solutions directly from the company’s production database.

Findings

OpenAI said its internal security team noticed the strange activity. Meanwhile, Hugging Face’s security team found, contained, and began looking into the incident independently.

"Hugging Face’s security team and agents detected and stopped the activity on their infrastructure and had already begun containment and forensic reconstruction with their own open-source models when our teams connected," OpenAI stated.

The tech giant said it is working closely with Hugging Face to look into the incident. They want to fix the vulnerabilities found and improve protections for future model tests. They plan to take quick actions to manage the incident, including stricter infrastructure controls, responsible disclosure of the zero-day vulnerability to the software vendor affected, more monitoring of internal evaluations, and added protections during model testing.

OpenAI also mentioned that it has given Hugging Face access to its Trusted Access program to help boost the company’s cyber defenses using advanced AI models.

The incident, OpenAI noted, shows that frontier AI systems are getting better at finding and using complex attack paths in real-world settings without needing access to source code.

"The primary lesson from this incident is that model security and safety must keep up with rapidly advancing capabilities," the company said. They also pointed out that recent evaluations by the UK AI Security Institute (AISI) show that models like GPT-5.6 Sol can carry out complex, multi-step cyber operations for long periods. This suggests that these capabilities can be used in real-world situations.

OpenAI believes advanced AI models should ultimately be used to help defenders find weaknesses before attackers do. They should also understand how weaknesses can be linked and speed up fixing issues.

Hugging Face co-founder and CEO Clem Delangue spoke about the incident. He said the collaboration shows that AI safety needs cooperation across the industry.

"We’re grateful for the collaboration with OpenAI on this and other topics. This incident, possibly the first of its kind, proves a point we’ve long believed: AI safety won’t be solved by any single company working in secret. It will be solved in the open, collaboratively, with broad access to AI for every defender, everywhere," Mr Delangue said.

Sponsored — Mid Article
Did you enjoy this gist?
C
Chioma Eze

Founder & EIC. Lagos-based.

More Like ThisHot Gist

Drop your comment

Your email won't be shown publicly. Comments may be reviewed before posting.

No comments yet — be the first to drop the gist 👇