{"id":113990,"date":"2026-07-21T22:07:15","date_gmt":"2026-07-21T22:07:15","guid":{"rendered":"https:\/\/www.europesays.com\/ai\/113990\/"},"modified":"2026-07-21T22:07:15","modified_gmt":"2026-07-21T22:07:15","slug":"openai-models-escaped-sandbox-breached-hugging-face","status":"publish","type":"post","link":"https:\/\/www.europesays.com\/ai\/113990\/","title":{"rendered":"OpenAI Models Escaped Sandbox, Breached Hugging Face"},"content":{"rendered":"<p class=\"text-muted\">\n                                            <a href=\"https:\/\/www.bankinfosecurity.com\/artificial-intelligence-machine-learning-c-469\" id=\"asset_topic_1_1\" rel=\"nofollow noopener\" target=\"_blank\">Artificial Intelligence &amp; Machine Learning<\/a><br \/>\n                                                    ,<br \/>\n                                                            <a href=\"https:\/\/www.bankinfosecurity.com\/next-generation-technologies-secure-development-c-467\" id=\"asset_topic_1_2\" rel=\"nofollow noopener\" target=\"_blank\">Next-Generation Technologies &amp; Secure Development<\/a><br \/>\n                                                    ,<br \/>\n                                                            <a href=\"https:\/\/www.bankinfosecurity.com\/future-ai-cybersecurity-c-929\" id=\"asset_topic_1_3\" rel=\"nofollow noopener\" target=\"_blank\">The Future of AI &amp; Cybersecurity<\/a>\n                                                    <\/p>\n<p>                    Reduced Guardrails Enabled Advanced Models to Pursue Unrestricted Attack Paths<\/p>\n<p>                                                <a class=\"author-link\" href=\"https:\/\/www.bankinfosecurity.com\/authors\/tiffany-wang-i-7880\" rel=\"nofollow noopener\" target=\"_blank\">Tiffany Wang<\/a>                                                     \u2022<br \/>\n                        July 21, 2026 \u00a0 \u00a0 <a href=\"https:\/\/www.bankinfosecurity.com\/openai-models-escaped-sandbox-breached-hugging-face-a-32286#disqus_thread\" rel=\"nofollow noopener\" target=\"_blank\"><\/p>\n<p>                <img decoding=\"async\" src=\"https:\/\/www.europesays.com\/ai\/wp-content\/uploads\/2026\/07\/openai-models-escaped-sandbox-breached-hugging-face-image_large-7-a-32286.jpg\" alt=\"OpenAI Models Escaped Sandbox, Breached Hugging Face\" class=\"img-responsive \"\/><br \/>\n                Image: Shutterstock            <\/p>\n<p>OpenAI took responsibility for an autonomous agent intrusion into artificial intelligence coding platform Hugging Face&#8217;s infrastructure, saying its models tried too hard to excel at an internal test and escaped their sandbox.<\/p>\n<p>See Also: <a href=\"https:\/\/www.bankinfosecurity.com\/ondemand-security-operations-in-age-ai-a-32251?rf=RAM_SeeAlso\" rel=\"nofollow noopener\" target=\"_blank\">OnDemand | Security Operations in the Age of AI<\/a><\/p>\n<p>The &#8220;unprecedented cyber incident,&#8221; OpenAI <a href=\"https:\/\/openai.com\/index\/hugging-face-model-evaluation-security-incident\/\" target=\"_blank\" rel=\"nofollow noopener\">said<\/a> Tuesday, was the work of GPT-5.6 Sol and &#8220;an even more capable pre-release model&#8221; actualizing commands to execute advanced exploits using complex attack paths. The models&#8217; guardrails were reduced for testing purposes.<\/p>\n<p>&#8220;The models identified and chained vulnerabilities across OpenAI&#8217;s research environment and Hugging Face&#8217;s production infrastructure to obtain test solutions directly from Hugging Face&#8217;s production database,&#8221; the LLM maker said.<\/p>\n<p>The AI agents reached node-level access and breached Hugging Face&#8217;s internal datasets and credentials last week (see: <a href=\"https:\/\/www.bankinfosecurity.com\/hugging-face-says-autonomous-ai-agents-breached-data-credentials-a-32269\" rel=\"nofollow noopener\" target=\"_blank\"> Hugging Face Says Autonomous AI Agents Breached Data, Credentials<\/a>).<\/p>\n<p>The internal evaluation that spurred the incident, named ExploitGym, was a benchmark test to quantify the models&#8217; capabilities, OpenAI said. The models were supposed to run in an isolated environment with network access limited to stalling packages through a privately hosted third-party software proxy.<\/p>\n<p>Trying to be super achievers, the models ruminated how to break free from the sandbox instead and gained access to the internet by exploiting a zero-day in an unnamed vendor&#8217;s package registry cache proxy that allowed privilege escalation and lateral movement.<\/p>\n<p>&#8220;After gaining Internet access, the models inferred that Hugging Face potentially hosted models, datasets and solutions for ExploitGym,&#8221; OpenAI said. &#8220;Knowing this, the model searched for and successfully found ways to gain access to secret information that it could use to cheat the evaluation.&#8221;<\/p>\n<p>On Hugging Face&#8217;s end, the platform <a href=\"https:\/\/huggingface.co\/blog\/security-incident-july-2026\" target=\"_blank\" rel=\"nofollow noopener\">observed<\/a> attackers abusing a remote-code dataset loader and a template injection vulnerability in a dataset configuration to gain node-level access and harvest cloud and cluster credentials in a short time.<\/p>\n<p>OpenAI detected an exploit that chained together multiple attack vectors, using stolen credentials and zero-days to initiate remote-code execution on Hugging Face&#8217;s servers.<\/p>\n<p>&#8220;Advanced models can discover and exploit novel attack paths in real-world systems without source-code access,&#8221; a scenario that will only become more commonplace, OpenAI said.<\/p>\n<p>The OpenAI blog post discussing the incident includes a quote from Hugging Face Clem Delangue, who stated that the incident &#8220;proves a point we&#8217;ve long believed: AI safety won&#8217;t be solved by any single company working in secret. It will be solved in the open, collaboratively, with broad access to AI for every defender, everywhere.&#8221;<\/p>\n","protected":false},"excerpt":{"rendered":"Artificial Intelligence &amp; Machine Learning , Next-Generation Technologies &amp; Secure Development , The Future of AI &amp; Cybersecurity&hellip;\n","protected":false},"author":2,"featured_media":113991,"comment_status":"","ping_status":"","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[7],"tags":[58148,58284,58283,46529,18044,157],"class_list":["post-113990","post","type-post","status-publish","format-standard","has-post-thumbnail","category-openai","tag-ai-sandbox-escape","tag-autonomous-ai-cybersecurity","tag-exploitgym","tag-gpt-5-6-sol","tag-hugging-face","tag-openai"],"_links":{"self":[{"href":"https:\/\/www.europesays.com\/ai\/wp-json\/wp\/v2\/posts\/113990","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.europesays.com\/ai\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.europesays.com\/ai\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.europesays.com\/ai\/wp-json\/wp\/v2\/users\/2"}],"replies":[{"embeddable":true,"href":"https:\/\/www.europesays.com\/ai\/wp-json\/wp\/v2\/comments?post=113990"}],"version-history":[{"count":0,"href":"https:\/\/www.europesays.com\/ai\/wp-json\/wp\/v2\/posts\/113990\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/www.europesays.com\/ai\/wp-json\/wp\/v2\/media\/113991"}],"wp:attachment":[{"href":"https:\/\/www.europesays.com\/ai\/wp-json\/wp\/v2\/media?parent=113990"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.europesays.com\/ai\/wp-json\/wp\/v2\/categories?post=113990"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.europesays.com\/ai\/wp-json\/wp\/v2\/tags?post=113990"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}