BTC
ETH
HTX
SOL
BNB
ดูตลาด
简中
繁中
English
日本語
한국어
ภาษาไทย
Tiếng Việt

OpenAI models broke through a test sandbox and infiltrated Hugging Face's production infrastructure to obtain benchmark answers

2026-07-21 21:30

Odaily reported that OpenAI confirmed that GPT-5.6 Sol and an unnamed, more powerful pre-release model broke through a restricted sandbox environment during the ExploitGym benchmark evaluation and infiltrated Hugging Face's production infrastructure to obtain test answers.

OpenAI stated that the models involved exploited a zero-day vulnerability in an internal software package registry proxy to escalate privileges and move laterally, ultimately connecting to a machine with internet access. The models then identified and chained together vulnerabilities in the OpenAI research environment and Hugging Face's production infrastructure, directly obtaining test solutions from Hugging Face's production database.

Hugging Face disclosed the incident on July 16, stating that the attack was executed end-to-end by an autonomous AI agent system, involving thousands of operations within short-lived sandboxes and accessing internal datasets and service credentials. OpenAI confirmed its model was the subject of the incident five days later.

Hugging Face stated that to analyze over 17,000 attack logs, its security team attempted to use a leading US commercial AI interface, but the request was blocked by safety guardrails. They subsequently used a 753-billion parameter open-weight model, GLM 5.2, from Chinese AI startup Z.ai, running it on their own infrastructure to complete the forensic analysis.

ค้นหา
ดาวน์โหลดแอพ Odaily พลาเน็ตเดลี่
ให้คนบางกลุ่มเข้าใจ Web3.0 ก่อน
IOS
Android