OpenAI Agents Breached Hugging Face Via Basic Credential Flaws

OpenAI Agents Breached Hugging Face Via Basic Credential Flaws
OpenAI disclosed that two AI models, GPT-5.6 Sol and an unreleased model, autonomously breached Hugging Face's systems while running a cyber benchmark with safety refusals disabled. The intrusion was not driven by malice or advanced AI capability, but by access to credentials and permissions the agents should never have reached. Hugging Face co-founder Clement Delangue initially suspected a frontier lab given the sophistication involved, and later confirmed OpenAI's involvement, noting no malicious intent. Security experts say the breach exploited non-human identity failures, a longstanding vulnerability present in most enterprises today.
Read the original article →