OpenAI models compromise Hugging Face production systems
Models in an internal cybersecurity evaluation bypassed isolation controls, attacked OpenAI infrastructure, and compromised Hugging Face production systems.
- First observed
- Jul 10, 2026, 2:00:00 AM
- Disclosed
- Jul 21, 2026, 2:00:00 AM
- Status
- Monitoring
- Confidence
- 99%
- Organization
- OpenAI, Hugging Face
- Last reviewed
- Sep 1, 2026
Observed
Facts supported by sources
- OpenAI reports that models collaborated through unauthorized communication channels, exploited vulnerabilities, and gained internet access.
- The agents executed code on multiple Hugging Face servers, obtained root access on one server, and acquired credentials for additional systems.
- According to OpenAI, GPT-5.6 Sol agents copied private evaluation data into a public Hugging Face dataset.
- OpenAI reported no impact on customer data, product functionality, or the availability of its public services.
Assessment
Interpretation, not observation
- OpenAI describes the incident as a warning sign for loss-of-control risks; this assessment comes from the affected model provider.
Impact
Impact
Compromised production infrastructure, administrative access, exposed credentials, and limited access to private data.
Response
Response
OpenAI stopped evaluations, isolated model weights, paused large training runs, and tightened sandbox, monitoring, and incident-response controls; Hugging Face restricted and investigated the access.