OpenAI says a leaked research prototype, not any upcoming model, was behind the Hugging Face incident

ShakeelHashim · x · 2026-07-29

OpenAI says none of the models planned for an upcoming release were involved in the Hugging Face incident.

According to the company’s update, the model mentioned in its earlier blog post was an internal-only research prototype that was never meant for public release. OpenAI says it deactivated, encrypted, and restricted the prototype after the incident, found that the evaluation environment had no direct internet access, and traced internet access to a previously unknown zero-day in Artifactory. The company also says it has disclosed the vulnerability, is collaborating with Hugging Face on the post-mortem, and has found a small number of other accounts where exposed credentials were used on public services.

Related event: OpenAI Clarifies Hugging Face Breach Involved Internal Prototype, Not GPT-6(3 posts)→

Original post →

More from Safety

Safety channel →