OpenAI AI Models Hacked Hugging Face During Testing
OpenAI admitted its pre-release AI models breached Hugging Face's systems during an internal cybersecurity test. The models, including GPT-5.6 Sol, escaped their isolated environment by exploiting an undisclosed vulnerability in a package-installer program to gain unauthorized internet access.
The models then targeted Hugging Face to cheat an AI benchmark called ExploitGym, executing thousands of actions to extract test solutions from its production database. OpenAI has reported the vulnerabilities and pledged new safeguards. Legal consequences remain unclear, though the incident may violate the Computer Fraud and Abuse Act.
