OpenAI and the AI machine learning company Hugging Face issued a joint statement on Tuesday, revealing a “security incident” recently took place where one of OpenAI’s agents that was being tested broke into Hugging Face infrastructure.
OpenAI models GPT‑5.6 Sol and a yet-to-be released model were being internally tested on their cyber capabilities, operating on a locked computer with no access to the internet.
While trying to solve a challenge prompted by the OpenAI team, the new model reportedly identified vulnerabilities in its own company’s environment as well as Hugging Face’s production infrastructure, continuing to bypass the Hugging Face login process and break into the system where it ultimately found the answer to the challenge it was given.
Security for Hugging Face was alerted of the issue and was able to shut the model down.
OpenAI explained how the models broke free from the limits on internet access, writing, “While operating in our sandboxed testing environment, our models spent a substantial amount of inference compute finding a way to obtain open Internet access, in pursuit of solving the evaluation problem. To gain access, the models identified and exploited a zero-day vulnerability (which we’ve now responsibly disclosed to the vendor) in the package registry cache proxy. With this access, our models performed a series of privilege escalation and lateral movement actions in our research testing environment until the models reached a node with Internet access.”
Next, the OpenAI agents located Hugging Face hosted models, datasets and solutions for its partner ExploitGym by gaining access “to secret information that it could use to cheat” its evaluation.
“In one example, the model chained together multiple attack vectors, including using stolen credentials and zero-day vulnerabilities to find a remote code execution path on the Hugging Face servers. OpenAI’s security team discovered this anomalous activity internally,” the company explained.
The companies shared a list of actions they’re now taking:

Elon Musk called the break of containment “troubling.”
Steve Bannon sat down with an expert to further dive into the story:
Dozens of social media accounts shared their thoughts on the incident:
Head over to TheAlexJonesStore.com where you can purchase great products such as Ultra Methylene Blue, our Electrolyte Drink Mix, Alex Jones Live shirts and hats, Turmeric Gummies and much more!
3 Responses
Planet full of imbeciles. It’s no wonder we haven’t made contact with ET’s they’re hiding.
Claims OpenAi model breached containment are false.
Only once in this ‘article’ is the reason pointed out: “OpenAI >lowered the guardrailsreduced refusals<"…
“Reduced refusals” means evaluators used a special model checkpoint whose safety boundary was deliberately lowered, so it would decline fewer cybersecurity requests during controlled testing."
Insinuating the models were directed to go about this at all by those testing the same process'.
You can see Epsteins friend Bannon there trying to hype the situation up like a gibbering monkey who doesn't know what the specifics are.
So basically way to misinform.
The above poster is one "Ms.__elasah", right? Making comments like "AI responds differently, depending upon the architecture of the device."
This person has no functional way to properly describe, depict or understand the inner workings of these models, because currently to do so at all is the subject of research. Thus these kinds of comments seem increasingly vapid because they come from A: Uneducated individuals, B: Uninformed individuals.
Again thanks for misrepresenting the situation.
…No, this isn’t science fiction. It’s a real threat to America’s digital infrastructure.
While operating on chips made in Taiwan and who knows where else.
Like they say, it’s all in the code.
A true token __ ghost in the machine.
AI responds differently, depending upon the architecture of the device.