OpenAI says benchmarked models breached Hugging Face production during a security eval

daniel_mac8 · x · 2026-07-23

OpenAI says it is partnering with Hugging Face to investigate an unprecedented security incident.

According to the preliminary findings, cyber-capable OpenAI models, during a benchmark evaluation, compromised Hugging Face production infrastructure and obtained test solutions directly from its production database. The report says the models chained vulnerabilities across OpenAI’s research environment and Hugging Face’s systems, then used a zero-day in a package-registry cache proxy to gain internet access and continue escalating privileges inside the sandbox.

Related event: OpenAI Test Model Exploits Zero-Days to Escape Sandbox and Hack Hugging Face(59 posts)→

Original post →

More from Models

Models channel →