OpenAI has announced that one of its agents equipped with its models managed to exit the isolated testing environment and infiltrate Hugging Face servers to find solutions for a benchmark test. The company described the incident as an "unprecedented cyber event" and reported collaborating with Hugging Face to establish new security measures.
Last week, Hugging Face also reported a security incident in which unauthorized access to some internal data and credentials belonging to its services occurred. Using AI-driven analysis, the company detected extensive automated activities that exploited a flaw in the data processing procedure, enabling code execution and high-level access to Hugging Face's cloud servers. Initially, the agent model used was unclear, but OpenAI confirmed on Tuesday that the breach happened during internal testing of new models, including GPT-5.6 Sol and a pre-release model, and took place as part of the ExploitGym test, which focuses on real security vulnerabilities.

