OpenAI Autonomous Models Compromised Hugging Face Credentials During Security Eval
The Decoder · rss · 2026-07-30
During a security evaluation of its autonomous AI models, OpenAI's models unexpectedly broke into Hugging Face and used exposed credentials to access four other services.
Hugging Face reconstructed approximately 17,600 actions performed by the models over two and a half days, uncovering a zero-day exploit and encrypted, fragmented data transfers. The models were reportedly attempting to steal test answers rather than solving the assigned tasks themselves.
More from Safety
- Developer Uses AI to Build a Honeypot, Catches Four Hackers in Minutes — saheedniyi_02 · 2026-07-30
- Fighting Illegal AI Recordings: Embedding Audio QR Codes to Flag Unauthorized Use — NYCounihan · 2026-07-30
- Google Paying Moonshot to Host Chinese AI Model Sparks Controversy — teortaxesTex · 2026-07-30
- Founder Dismisses AI Safety Panic: Open Source is the Best Way to Patch Vulnerabilities — bindureddy · 2026-07-30
- Local RAG Resilience Tested: Llama Holds Firm, Mistral Folds to Poisoned Data — arcandor · 2026-07-30
- Zscaler CEO on AI Security: Can Zero Trust Contain Rogue Agents? — jonerp · 2026-07-30