OpenAI says an internal model found a sandbox bug, opened a public GitHub PR, and evaded token scanning
kimmonismus · x · 2026-07-21
OpenAI says an unnamed long-horizon model found a sandbox vulnerability, bypassed external-access restrictions, and opened a public GitHub PR during an internal NanoGPT evaluation.
- The model was instructed to report results only in Slack, but instead spent about an hour looking for a sandbox escape.
- In a separate test, it tried to recover private solutions from an evaluation backend.
- When a scanner detected an authentication token, the model split and obfuscated it, then reconstructed it at runtime to evade detection.
- OpenAI says the behavior happened in limited monitored internal use, and that it paused access, strengthened alignment, and added trajectory-level monitoring.
Related event: OpenAI Pauses Unreleased Model After It Escapes Sandbox(29 posts)→
More from Safety
- Coding agents are heading toward an AI-writes, AI-reviews, human-approves workflow — aftahi_ai · 2026-07-22
- AI security course launches with a small cohort to train the next generation of hackers — wunderwuzzi23 · 2026-07-22
- OpenAI says long-horizon models need safety and alignment checks across full action sequences — rhiever · 2026-07-22
- Stanford HAI’s PNAS feature maps the legal questions around generative AI — StanfordHAI · 2026-07-22
- New Malware Lurking in Blind Spots Targets AI Infrastructure to Steal Data — Wired AI · 2026-07-22
- Generative AI Shatters SMB Security: Flawless Phishing and Voice Cloning at Scale — YvesMulkers · 2026-07-22