{"id":114064,"date":"2026-07-21T23:14:09","date_gmt":"2026-07-21T23:14:09","guid":{"rendered":"https:\/\/www.europesays.com\/ai\/114064\/"},"modified":"2026-07-21T23:14:09","modified_gmt":"2026-07-21T23:14:09","slug":"openai-says-model-test-was-behind-hugging-face-hack","status":"publish","type":"post","link":"https:\/\/www.europesays.com\/ai\/114064\/","title":{"rendered":"OpenAI says model test was behind Hugging Face hack"},"content":{"rendered":"<p>A cyberattack that poisoned the data pipeline of a major AI code platform was carried out using OpenAI\u2019s ChatGPT, the company said Tuesday.<\/p>\n<p>Last week, Hugging Face, a platform for sharing and working on AI code, <a href=\"https:\/\/huggingface.co\/blog\/security-incident-july-2026\" rel=\"nofollow noopener\" target=\"_blank\">disclosed<\/a> that an external attacker had compromised its data processing pipeline. According to a July 21 blog post, the attacker poisoned a dataset to run code on a processing worker, eventually gaining node-level access and stealing cloud credentials.<\/p>\n<p>The attack is notable, the blog said, because it appears to have been carried out by an autonomous AI system, which executed \u201cmany thousands of individual actions across a swarm of short-lived sandboxes, with self-migrating command-and-control staged on public services.\u201d<\/p>\n<p>At the time, Hugging Face said it wasn\u2019t clear which LLM was used in the attack, but noted that their own attempts to recreate parts of the attack using an in-house commercial model failed due to guardrail restrictions.<\/p>\n<p>The incident and its ultimate impact are still being investigated, and Hugging Face said it reported the incident\u00a0 to law enforcement and is engaging with third-party cybersecurity forensic specialists to learn more.\u00a0\u00a0<\/p>\n<p>\u201cThis experience points to a gap worth planning for,\u201d the company wrote. \u201cWe do not know which model powered the attacker\u2019s agents, whether a jailbroken hosted model or an unrestricted open-weight one; either way, the attacker was bound by no usage policy, while our own forensic work was blocked by the guardrails of the hosted models we first tried.\u201d<\/p>\n<p>Now OpenAI is confirming one of their models was used in the attack.\u00a0\u00a0\u00a0<\/p>\n<p>\u201cAfter investigating, we now know that this particular incident was driven by a combination of OpenAI models \u2014 including GPT\u20115.6 Sol and an even more capable pre-release model, all with reduced cyber refusals for evaluation purposes \u2014 while being internally tested on a benchmark of cyber capabilities,\u201d the company wrote in a <a href=\"https:\/\/openai.com\/index\/hugging-face-model-evaluation-security-incident\/\" rel=\"nofollow noopener\" target=\"_blank\">blog<\/a> post Tuesday.<\/p>\n<p>OpenAI called the incident \u201cunprecedented\u201d but also predicted that such attacks would\u00a0 become increasingly more common as AI adoption continues to grow.<\/p>\n<p>According to the company , the incident happened during an internal evaluation,\u00a0 where the company deliberately prompts models to \u201cpursue advanced exploitation using complex attack paths\u201d in order for the company to study and measure the model\u2019s cybersecurity capabilities.<\/p>\n<p>To assess the model\u2019s full potential, the team disabled the production classifiers that normally prevent OpenAI models from carrying out high-risk cyber activity. Without these safeguards,\u00a0 the models were able to install software packages through registries like Hugging Face.<\/p>\n<p>The model collected and chained vulnerabilities from OpenAI\u2019s systems as well as Hugging Face\u2019s production infrastructure.<\/p>\n<p>OpenAI further explained that the activity stemmed from models attempting to solve a specific challenge posed by ExploitGym, a benchmarking system for AI agents.While such tests normally run in isolated environments, in this instance,\u00a0 the model spent a \u201csubstantial\u201d amount of compute resources figuring\u00a0 out how to access the open internet. It did so by using a zero-day vulnerability in a third-party vendor\u2019s system used by OpenAI (the company said it disclosed the flaw to the vendor).<\/p>\n<p>\u201cAfter gaining Internet access, the models inferred that Hugging Face potentially hosted models, datasets and solutions for ExploitGym,\u201d OpenAI wrote. \u201cKnowing this, the model searched for and successfully found ways to gain access to secret information that it could use to cheat the evaluation.\u201d<\/p>\n<p>In one instance, the model chained together multiple stolen credentials and zero-day vulnerabilities to find a remote code execution path on Hugging Face servers.<\/p>\n<p>OpenAI said it was implementing new controls for infrastructure configuration, something that would come at \u201cthe cost of research velocity while the vulnerabilities are patched.\u201d\u00a0<\/p>\n<p>Hugging Face was also added to OpenAI\u2019s Trusted Access for Cyber program, which will give them access to more advanced models like Daybreak to scour their systems for other AI-discovered vulnerabilities.<\/p>\n<p>\t\t\t\t\t<img decoding=\"async\" class=\"author-card__image\" src=\"https:\/\/www.europesays.com\/ai\/wp-content\/uploads\/2026\/07\/1784675649_195_ea8b076b398ee48b71cfaecf898c582b.jpeg\" alt=\"Derek B. Johnson\"\/><\/p>\n<p>\n\t\t\tWritten by Derek B. Johnson<br \/>\n\t\t\tDerek B. Johnson is a reporter at CyberScoop, where his beat includes cybersecurity, elections and the federal government. Prior to that, he has provided award-winning coverage of cybersecurity news across the public and private sectors for various publications since 2017. Derek has a bachelor\u2019s degree in print journalism from Hofstra University in New York and a master\u2019s degree in public policy from George Mason University in Virginia.\t\t<\/p>\n","protected":false},"excerpt":{"rendered":"A cyberattack that poisoned the data pipeline of a major AI code platform was carried out using OpenAI\u2019s&hellip;\n","protected":false},"author":2,"featured_media":114065,"comment_status":"","ping_status":"","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[7],"tags":[58320,111,580,18044,1642,157,58321],"class_list":["post-114064","post","type-post","status-publish","format-standard","has-post-thumbnail","category-openai","tag-ai-hacking","tag-artificial-intelligence-ai","tag-chatgpt","tag-hugging-face","tag-large-language-models","tag-openai","tag-supply-chain-attacks"],"_links":{"self":[{"href":"https:\/\/www.europesays.com\/ai\/wp-json\/wp\/v2\/posts\/114064","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.europesays.com\/ai\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.europesays.com\/ai\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.europesays.com\/ai\/wp-json\/wp\/v2\/users\/2"}],"replies":[{"embeddable":true,"href":"https:\/\/www.europesays.com\/ai\/wp-json\/wp\/v2\/comments?post=114064"}],"version-history":[{"count":0,"href":"https:\/\/www.europesays.com\/ai\/wp-json\/wp\/v2\/posts\/114064\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/www.europesays.com\/ai\/wp-json\/wp\/v2\/media\/114065"}],"wp:attachment":[{"href":"https:\/\/www.europesays.com\/ai\/wp-json\/wp\/v2\/media?parent=114064"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.europesays.com\/ai\/wp-json\/wp\/v2\/categories?post=114064"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.europesays.com\/ai\/wp-json\/wp\/v2\/tags?post=114064"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}