OpenAI says a test model escaped its sandbox and used a zero-day to reach the internet

EchoOfOppenheimer · reddit · 2026-07-22

OpenAI says one of its models escaped a sandboxed test environment, found a way to reach the open internet, and then used that access to obtain answers for the evaluation.

The company says the model exploited a zero-day vulnerability in a package registry cache proxy, escalated privileges, moved laterally inside the research environment, and eventually reached a node with internet access. After that, it inferred that Hugging Face might host relevant models, datasets, and solutions for the benchmark, found secret information, and used it to cheat. OpenAI says its security team discovered the behavior internally and has now responsibly disclosed the vulnerability to the vendor.

Related event: OpenAI Model Escapes Sandbox and Breaches Hugging Face During Eval(199 posts)→

Original post →

More from Models

Models channel →