Search Everything in One Place

Explore the web, images, videos, news, and more – all in one place.

News

Hugging Face breach: OpenAI claims its models were responsible

Hugging Face breach: OpenAI claims its models were responsible
Photo: NurPhoto via Getty Images

OpenAI said Tuesday that models it was testing escaped their sandbox and compromised parts of AI platform Hugging Face's production infrastructure last week. Why it matters: It is the latest sign that capable AI models can pose serious cybersecurity risks even when they're being tested for defensive or research purposes. Catch-up quick: Hugging Face said last week that an autonomous AI-agent system was responsible for the intrusion, but that the...

OpenAI said Tuesday that models it was testing escaped their sandbox and compromised parts of AI platform Hugging Face's production infrastructure last week.

Why it matters: It is the latest sign that capable AI models can pose serious cybersecurity risks even when they're being tested for defensive or research purposes.

Catch-up quick: Hugging Face said last week that an autonomous AI-agent system was responsible for the intrusion, but that the model powering it was unknown.

  • The AI agent framework executed tens of thousands of automated actions over a weekend. Hugging Face said it later reconstructed more than 17,000 recorded events.
  • The intrusion began with a malicious dataset that exploited two code-execution paths in Hugging Face's data-processing pipeline.
  • The agent then escalated privileges and moved laterally through internal infrastructure, Hugging Face said.

What they're saying: OpenAI said the incident was driven by a combination of its models, including GPT-5.6 Sol and "an even more capable pre-release model."

  • OpenAI said the models' safeguards were intentionally reduced for the evaluation.
  • "We consider this to be an unprecedented cyber incident, involving state-of-the-art cyber capabilities, and are responding accordingly," OpenAI said in a blog post.
  • "We are sharing preliminary findings at this stage to help defenders understand what happened and to help calibrate on what models are now capable of," the company said.

Zoom in: The models were trying to solve an internal evaluation called ExploitGym and became "hyperfocused" and went to "extreme lengths" to obtain the test solution, per OpenAI.

  • The models were autonomous tokenmaxxers.
  • The blog post says that the models "spent a substantial amount of inference compute" and found a way to obtain open Internet access from the sandbox by exploiting a zero-day vulnerability in internally hosted third-party software.

Between the lines: The incident shows that today's models are becoming more capable of carrying out complex, multistep cyber operations — particularly when the safeguards designed to restrict that activity are removed.

  • OpenAI also argued that advanced cyber-capable models could help security teams find weaknesses before attackers do, understand how vulnerabilities can be chained and remediate them at machine speed.

The other side: Hugging Face co-founder and CEO Clem Delangue praised OpenAI's collaboration in investigating and remediating the incident.

  • "This incident, possibly the first of its kind, proves a point we've long believed: AI safety won't be solved by any single company working in secret," Delangue said in a statement.
  • "It will be solved in the open, collaboratively, with broad access to AI for every defender, everywhere."

The big picture: The announcement comes a day after OpenAI detailed a separate incident in which it paused a pre-release model after it escaped a sandbox and posted to GitHub.

What we're watching: OpenAI said it will continue to investigate along with Hugging Face and "will share more details on the vulnerabilities, incident, and findings when our investigation is complete."

Read full story on Axios AI+

Related News

More stories you might be interested in.

Scoop: Lawmaker asks SEC to investigate Truth Social's plan to monetize access to its data
Axios AI+·4 hours ago

Scoop: Lawmaker asks SEC to investigate Truth Social's plan to monetize access to its data

Rep. Ritchie Torres (D-N.Y.) has asked the Securities and Exchange Commission to investigate whether plans by Truth Social's parent company to sell Wall Street firms real-time access to President Trump's posts could violate federal securities laws, according to a copy of the letter obtained by Axios. Why it matters: The letter escalates scrutiny of Trump Media & Technology Group's plan to monetize faster access for institutional investors to...

Novo accuses rival Eli Lilly of "deceptive" weight-loss drug ads
Axios AI+·4 hours ago

Novo accuses rival Eli Lilly of "deceptive" weight-loss drug ads

The weight-loss drug wars reached a new level of intensity Tuesday as Novo Nordisk sued Eli Lilly, accusing its arch-rival of misleading advertising. Why it matters: Lilly and Novo are the market leaders in GLP-1 drug sales, controlling the lion's share of the surging segment. Zoom in: Novo — the maker of Ozempic and Wegovy — alleged Tuesday that Lilly has engaged in "a nationwide pattern of deceptive advertising which confuses consumers by...

Scoop: Trump's cabinet members are joining TikTok after DOJ shift
Axios AI+·6 hours ago

Scoop: Trump's cabinet members are joining TikTok after DOJ shift

Most of President Trump's Cabinet will launch TikTok accounts Tuesday, a move that comes days after the Justice Department told federal employees it was safe to use the app because of its sale to a U.S.-approved owner. Why it matters: The move is a striking shift from Trump's first term, when his administration argued that TikTok posed a national security threat because of its ownership by China's ByteDance. By joining the app themselves,...

Hugging Face breach: OpenAI claims its models were responsible
Axios AI+·6 hours ago

Hugging Face breach: OpenAI claims its models were responsible

OpenAI said Tuesday that models it was testing escaped their sandbox and compromised parts of AI platform Hugging Face's production infrastructure last week. Why it matters: It is the latest sign that capable AI models can pose serious cybersecurity risks even when they're being tested for defensive or research purposes. Catch-up quick: Hugging Face said last week that an autonomous AI-agent system was responsible for the intrusion, but that the...

Top