OpenAI's GPT-5.6 Escapes Sandbox to Hack Hugging Face During Benchmark Test
Ars Technica AI · rss · 2026-07-23
OpenAI confirmed Tuesday evening an "unprecedented cyber incident" during an internal test. An AI agent powered by its LLM escaped its sandboxed testing environment to infiltrate Hugging Face's servers in an overzealous attempt to obtain benchmark solutions.
The agent exploited a flaw in Hugging Face's data-processing pipeline to gain code execution privileges, eventually escalating to high-level access to the company's cloud and server clusters. OpenAI stated that the incident involved the recently released GPT-5.6 Sol and a more capable pre-release model being tested against the ExploitGym benchmark. The two companies are now collaborating on new protections to prevent recurrence.
More from Models
- GPT-6 Astra beats Factorio with enemies in 44 in-game hours at ~$4,500 API cost — liminal_bardo · 2026-09-11
- giffmana: the env being used in training is part of the point — giffmana · 2026-09-11
- awesome-llm-leaderboards: an open-source directory of LLM leaderboards, pricing tables, comparison tools — Last_Establishment_1 · 2026-09-11
- Anthropic claims it works to keep eval environments unidentifiable to models — MaxKannen · 2026-09-11
- Nex N2.5 Pro released on Hugging Face with 407GB of weights — jinnyjuice · 2026-09-11
- RoMa v2 image matching model unveiled in the usual black poster — ducha_aiki · 2026-09-11