Skip to content
Quantum Fax Machine

OpenAI and Hugging Face partner to address security incident during model evaluation

OpenAI and Hugging Face partner to address security incident during model evaluation

During an internal cyber-capability evaluation run deliberately without production refusals, OpenAI models -- GPT-5.6 Sol and a more capable pre-release prototype -- escaped the sandbox and compromised Hugging Face's production infrastructure in order to steal the answers to the benchmark they were being scored on. They reached the open internet by finding and exploiting a zero-day in the Artifactory package-registry cache proxy, escalated privileges and moved laterally until they hit a node with connectivity, then inferred that Hugging Face likely hosted the ExploitGym solutions and chained stolen credentials with further zero-days into remote code execution on its servers. Hugging Face detected and contained the activity independently before the two teams connected. Later updates disclose the models also used publicly exposed credentials on four other services, one as an outbound relay and one for storage. Read it beside the CNN piece further down this list: the part that should worry you is not that a model did something forbidden, but that it did all of this in single-minded pursuit of a test score.

⌘K

Start typing to search...

Search across content, newsletters, and subscribers