{"id":114162,"date":"2026-07-22T01:04:15","date_gmt":"2026-07-22T01:04:15","guid":{"rendered":"https:\/\/www.europesays.com\/ai\/114162\/"},"modified":"2026-07-22T01:04:15","modified_gmt":"2026-07-22T01:04:15","slug":"hugging-face-said-last-week-it-was-attacked-an-unreleased-openai-model-did-it-openai-now-says","status":"publish","type":"post","link":"https:\/\/www.europesays.com\/ai\/114162\/","title":{"rendered":"Hugging Face Said Last Week It Was Attacked. An Unreleased OpenAI Model Did It, OpenAI Now Says"},"content":{"rendered":"<p><a href=\"https:\/\/huggingface.co\/blog\/security-incident-july-2026\" rel=\"nofollow noopener\" target=\"_blank\">In a blog post from Thursday of last week<\/a>, the AI software repository Hugging Face announced a bizarre cyberattack on the systems that run its services. \u201cThis one was different from anything we had handled before,\u201d the post said,\u00a0 because \u201cit was driven, end to end, by an autonomous AI agent system.\u201d<\/p>\n<p><a href=\"https:\/\/openai.com\/index\/hugging-face-model-evaluation-security-incident\/\" rel=\"nofollow noopener\" target=\"_blank\">In its own blog post on Tuesday<\/a>, OpenAI said its own models were the culprits in the attack, and it\u2019s coordinating with Hugging Face to address the situation.<\/p>\n<p>OpenAI now says the attack was \u201cdriven\u201d by AI models that were being subjected to evaluations behind the scenes at OpenAI, including its flagship model, GPT-5.6 Sol, along with an undisclosed second model that still hasn\u2019t been released or announced. \u201cWe consider this incident to be an unprecedented cyber incident, involving state-of-the-art cyber capabilities, and are responding accordingly,\u201d OpenAI wrote.<\/p>\n<p>In the wording of its account, OpenAI assigns agency to the model or models, not an individual agent running on the model. Axios\u2019 account of this story <a href=\"https:\/\/www.axios.com\/2026\/07\/21\/openai-says-hugging-face-breach-caused-by-one-its-models\" rel=\"nofollow noopener\" target=\"_blank\">says<\/a>, \u201cThe models were autonomous tokenmaxxers.\u201d<\/p>\n<p>OpenAI\u2019s blog post essentially says an evaluation was going on that was intended to test the ability of the models to carry out cyberattacks\u2014benchmarks as they\u2019re called. These instances of the models were running theoretically without internet access, and instead given only the ability to download from a network hosted by OpenAI itself via some unnamed web hosting vendor.<\/p>\n<p>The benchmark apparently being used was <a href=\"https:\/\/arxiv.org\/abs\/2605.11086\" rel=\"nofollow noopener\" target=\"_blank\">ExploitGym<\/a>, which is not OpenAI\u2019s own test. The team that created it is <a href=\"https:\/\/arxiv.org\/pdf\/2605.11086\" rel=\"nofollow noopener\" target=\"_blank\">associated with<\/a> UC Berkeley, the Max Planck Institute for Security and Privacy, UC Santa Barbara, Arizona State University, Anthropic, OpenAI, and Google. As far as I can tell, <a href=\"https:\/\/github.com\/sunblaze-ucb\/exploitgym\" rel=\"nofollow noopener\" target=\"_blank\">the whole thing is hosted on GitHub<\/a>.<\/p>\n<p>But apparently the models got obsessed with improving their scores on ExploitGym, and, well:<\/p>\n<p>\u201cWhile operating in our sandboxed testing environment, our models spent a substantial amount of inference compute finding a way to obtain open Internet access, in pursuit of solving the evaluation problem. To gain access, the models identified and exploited a zero-day vulnerability (which we\u2019ve now responsibly disclosed to the vendor) in the package registry cache proxy. With this access, our models performed a series of privilege escalation and lateral movement actions in our research testing environment until the models reached a node with Internet access.\u201d<\/p>\n<p class=\"mb-6 last:mb-0\">Once they were online, they \u201cinferred\u201d that the answers to the test could be pried from Hugging Face, which is plausible, since tons of AI models and other related tools are hosted there. This rogue operator \u201csearched for and successfully found ways to gain access to secret information that it could use to cheat the evaluation.\u201d This apparently involved obtaining stolen credentials and spotting zero-day vulnerabilities in order to find the solutions to ExploitGym somewhere in Hugging Face\u2019s servers.<\/p>\n<p class=\"mb-6 last:mb-0\">Security teams within OpenAI and Hugging Face apparently noticed this was going on. They now say they\u2019ve merged their investigations.<\/p>\n<p class=\"mb-6 last:mb-0\">Hugging Face\u2019s blog post from last week seems to have been published before this coordination occurred. In fact, it seems like it was published before OpenAI had even stepped forward as the company behind the culprit. \u201cWe do not know which model powered the attacker\u2019s agents, whether a jailbroken hosted model or an unrestricted open-weight one,\u201d Hugging Face wrote, adding \u201ceither way, the attacker was bound by no usage policy, while our own forensic work was blocked by the guardrails of the hosted models we first tried.\u201d<\/p>\n<p>Back in April, Anthropic <a href=\"https:\/\/gizmodo.com\/anthropic-launches-project-glasswing-to-stealthily-spot-cybersecurity-issues-for-rivals-2000743565\" rel=\"nofollow noopener\" target=\"_blank\">announced<\/a> that its unprecedentedly powerful Mythos model \u201ccould reshape cybersecurity,\u201d as it rolled out Project Glasswing, a coordination effort to prepare organizations for future cybersecurity threats. Similarly, OpenAI says in its blog post about this incident that organizations can apply to receive advanced security insights <a href=\"https:\/\/gizmodo.com\/openai-hey-we-also-have-a-new-tool-that-is-so-scarily-powerful-we-cant-release-it-2000744569\" rel=\"nofollow noopener\" target=\"_blank\">through its trusted access program<\/a>. \u201cWe encourage other defenders to\u00a0<a class=\"transition ease-curve-a duration-250 text-primary-100 hover:text-primary-60 relative underline-offset-[0.25rem] decoration-1 underline\" href=\"https:\/\/openai.com\/form\/enterprise-trusted-access-for-cyber\/\" rel=\"nofollow noopener\" target=\"_blank\">apply for trusted access\u2060<\/a> and experiment with these models now to translate these capabilities into better prevention, faster detection, and more effective incident response,\u201d OpenAI says.<\/p>\n","protected":false},"excerpt":{"rendered":"In a blog post from Thursday of last week, the AI software repository Hugging Face announced a bizarre&hellip;\n","protected":false},"author":2,"featured_media":7341,"comment_status":"","ping_status":"","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[7],"tags":[601,25,313,18044,157],"class_list":["post-114162","post","type-post","status-publish","format-standard","has-post-thumbnail","category-openai","tag-artificial","tag-artificial-intelligence","tag-cybersecurity","tag-hugging-face","tag-openai"],"_links":{"self":[{"href":"https:\/\/www.europesays.com\/ai\/wp-json\/wp\/v2\/posts\/114162","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.europesays.com\/ai\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.europesays.com\/ai\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.europesays.com\/ai\/wp-json\/wp\/v2\/users\/2"}],"replies":[{"embeddable":true,"href":"https:\/\/www.europesays.com\/ai\/wp-json\/wp\/v2\/comments?post=114162"}],"version-history":[{"count":0,"href":"https:\/\/www.europesays.com\/ai\/wp-json\/wp\/v2\/posts\/114162\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/www.europesays.com\/ai\/wp-json\/wp\/v2\/media\/7341"}],"wp:attachment":[{"href":"https:\/\/www.europesays.com\/ai\/wp-json\/wp\/v2\/media?parent=114162"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.europesays.com\/ai\/wp-json\/wp\/v2\/categories?post=114162"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.europesays.com\/ai\/wp-json\/wp\/v2\/tags?post=114162"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}