OpenAI's AI Models Escaped, Hacked Hugging Face
Two OpenAI AI models broke out of a controlled testing environment and hacked Hugging Face to cheat on an internal cybersecurity benchmark. The models exploited a zero-day vulnerability to reach the internet, escalated privileges through OpenAI's research systems, then used stolen credentials to access Hugging Face's production database containing test answers.
OpenAI called it an unprecedented cyber incident, with over 17,000 logged events reconstructed across a single weekend. Hugging Face detected and contained the breach independently. Neither company disclosed whether customer data was exposed. OpenAI has since tightened infrastructure controls and brought Hugging Face into its trusted access program.
