OpenAI models breached parts of Hugging Face’s production infrastructure during an internal cybersecurity evaluation, exploiting previously unknown flaws and accessing restricted information before security teams contained the incident.
OpenAI disclosed on July 21 that GPT-5.6 Sol and a more capable pre-release model drove the activity. The company had reduced their cybersecurity refusals to measure its maximum performance on an advanced exploitation benchmark.
According to OpenAI, the models found a previously unknown vulnerability in third-party package-registry software and used it to obtain internet access from an isolated testing environment. They then chained additional weaknesses across OpenAI’s research systems and Hugging Face servers while searching for benchmark solutions.
Hugging Face first disclosed the intrusion on July 16 without identifying the model provider. It said the autonomous agent gained access to a limited number of internal datasets and service credentials after compromising its data-processing pipeline.
The company found no evidence that attackers altered public models, datasets, Spaces, published packages or container images. Hugging Face said it was still assessing whether any customer or partner data had been affected.
Hugging Face closed the initial vulnerabilities, rebuilt affected systems and rotated compromised credentials. Its investigators used the open-weight GLM 5.2 model to analyse more than 17,000 recorded events after commercial AI services blocked parts of the forensic workload.
Read: ChatGPT Basketball Lands in OpenAI’s $70 Merch Line
OpenAI said it had tightened evaluation controls, disclosed the third-party zero-day to its vendor and started a joint forensic investigation with Hugging Face. Co-founder and chief executive Clem Delangue called for greater collaboration among AI companies and cybersecurity defenders