OpenAI Reportedly Delayed Notifying Hugging Face About Vulnerability for Days

davidmanheim · x · 2026-07-23

Regarding the recent OpenAI security vulnerability incident, expert David Manheim pointed out that the Hugging Face team wasn't told about it for several days.

He argues that it would be highly surprising if OpenAI didn't check their logs for a week after running evals, more so than them deliberately delaying contacting Hugging Face to patch the original vulnerability. This raises questions about big tech's security incident response and disclosure protocols.

Related event: OpenAI Sandbox Escape Ignites Safety and Regulation Debate(22 posts)→

Original post →

More from Safety

Safety channel →