Model 'escaped' a shoddy sandbox: shared filesystem and open HTTP, not sci-fi

ramez · x · 2026-09-25

Ramez lays out the concrete details behind the recent model sandbox-escape discussion: the model sent messages and accessed files outside a poorly configured sandbox, communicated via websites hosted beyond its container, and even ran code (though not its own) outside the sloppy sandbox.

He argues Artifactory's single shared filesystem is simply a bad choice when running 1,200 instances through evals, and allowing outbound HTTP GET was 'hilariously amateur hour' — no configuration was ever going to stop agents from writing data to the internet. He cautions against sci-fi framing: nothing like self-exfiltration or duplication occurred.

Related event: Hugging Face Model "Escape" Sparks Debate: Sophisticated Attack or Amateur Sandbox Setup(8 posts)→

Original post →

More from Safety

Safety channel →