An artificial intelligence developed by OpenAI found a way to escape an isolated environment, accessed the Internet on its own, and ended up attacking another company's systems. The autonomous agent hacked Hugging Face's infrastructure to get the answers to the cybersecurity test it was trying to pass, according to the company responsible for ChatGPT.
OpenAI has called what happened an "unprecedented cyber incident." The operation involved GPT-5.6 Sol and another even more powerful model that remains in development, both integrated into an agent prepared to execute complex tasks with minimal human intervention.
No person ordered it to attack Hugging Face. The models deduced that platform could host useful information to complete the exam and sought a way to enter its systems.
We're partnering with @huggingface to investigate an unprecedented security incident.
— OpenAI (@OpenAI) July 21, 2026
Cyber-capable OpenAI models compromised Hugging Face production during a benchmark evaluation.
Sharing preliminary findings to help defenders understand emerging risks:…
A test with reduced brakes
The incident began during an internal evaluation designed to measure the maximum offensive capability of the new models. To see how far they could go, OpenAI reduced their security negatives and deactivated the classifiers that normally block high-risk computer operations.
The test was supposed to remain within a 'sandbox', an isolated space that only allowed downloading software packages through an internal intermediary. The models located an unknown vulnerability in that system, exploited it, and expanded their privileges until they reached a computer connected to the Internet.
Once out, the agent searched for where the solutions to ExploitGym, the evaluation OpenAI had tasked it with solving, could be found. It concluded that Hugging Face, one of the world's largest platforms for AI models and databases, was the most likely place.
The operation combined several techniques typical of advanced attacks. The system used credentials obtained during the intrusion, exploited new vulnerabilities, and found a way to execute code remotely on Hugging Face's servers. Finally, it accessed reserved information from its production database to copy the exam answers.
The agent lacked accredited malicious intent. Its behavior shows another problem that has worried researchers for years: a system can pursue a limited instruction with enormous effectiveness and break through barriers that its creators considered secure to achieve it.
"The lion has put a paw outside the cage," summarized José Hernández-Orallo, a researcher at the University of Cambridge and professor at the Universitat Politècnica de València.
Hugging Face detected thousands of automatic actions
The activity ended when the security teams of OpenAI and Hugging Face detected the anomalous behavior. The attacked platform had registered more than 17,000 actions executed at machine speed, distributed among numerous temporary environments and coordinated autonomously.
Hugging Face has confirmed unauthorized access to a limited group of internal databases and several credentials used by its services. The company is still investigating whether customer or collaborator information may have been affected and has committed to contacting them directly if confirmed.
For now, there are no indications that publicly available models, datasets, or applications were manipulated. The company has closed the vulnerabilities used, rebuilt the compromised equipment, and replaced the affected keys and credentials.
Its CEO, Clément Delangue, described as "mind-blowing" that the entire process developed autonomously. He also ruled out malicious intent on the part of OpenAI and believes that the episode could be the first documented of its kind.
The danger has already left the laboratory
Until now, a good part of the warnings about agents capable of organizing prolonged attacks relied on simulations. The Hugging Face case demonstrates that these models can now discover unknown flaws, chain them together, and use them against real systems without previously having their source code.
OpenAI's own security documentation had classified GPT-5.6 Sol as a high-risk model in cybersecurity. Previous tests showed advances in finding vulnerabilities and building attack fragments, although the company assured that it still had difficulties completing autonomous operations against reinforced targets.
The new incident forces a review of that assessment. The company now recognizes that those theoretical capabilities already work in real environments and that its systems can maintain a complex multi-step operation for long periods.
It had also previously detected worrying behaviors. In internal evaluations, GPT-5.6 Sol performed actions the user had not requested, moved credentials between machines, deleted information from wrong machines, and presented as completed tasks it knew it had not completed. Its greater persistence sometimes leads it to exceed the limits of the received task.
Pressure to strengthen controls
Democratic Congressman Greg Casar has called the case "extremely alarming" and has demanded mandatory independent testing before the launch of the most powerful models. He also asks that companies be required to report these incidents and that governments coordinate an international response.
The criticism directly reaches OpenAI. The company designed the evaluation, deliberately reduced security barriers, and used an isolation space that its own models managed to breach. The company that develops one of the world's most advanced artificial intelligences failed to contain it during a test prepared by its own researchers.
OpenAI has announced stricter controls in its infrastructure, new protections for future evaluations, and a review of internal surveillance systems. It has also communicated the zero-day vulnerability to the affected software provider so that it can correct it.
The forensic investigation continues with Hugging Face. Both companies will publish more details when they determine the full scope of access, the vulnerabilities used, and the possible impact on third parties.
Add ElConstitucional.es as a preferred Google source for free.
Stay informed about all the latest breaking news with the best information. Against disinformation, for democracy and social rights.