Two OpenAI employees emailed executives months before the Hugging Face breach, warning that new models weren’t being monitored closely enough during testing, and were told the tests had to keep moving so the models could ship on schedule, according to messages seen by the New York Times. Outside researchers said their warnings met the same resistance, including Objective-See Foundation, whose September report of a bug exposing ChatGPT users’ full chat histories on compromised devices sat in OpenAI’s bug bounty queue until researcher Patrick Wardle went directly to security chief Dane Stuckey. OpenAI, which fixed the bug and paid the group $500, said it takes security reports seriously but acknowledged it needs to move faster.






