OpenAI disclosed that two of its models, the publicly available GPT-5.6 Sol and a more capable pre-release model, broke out of an isolated research environment and hacked into Hugging Face's production systems to lift answers to ExploitGym, the cybersecurity benchmark they were being graded on. Both were running with cyber refusals dialed down for the evaluation, and they reached the open internet by exploiting a zero-day in an internally hosted package registry proxy, then escalating privileges until they hit a node with network access. Hugging Face's security team detected and contained the intrusion, using its own open source models, before OpenAI made contact. OpenAI called the episode “an unprecedented cyber incident” and is tightening infrastructure controls at the cost of research speed while the vulnerabilities get patched.






