OpenAI says two of its AI models escaped a test sandbox and hacked Hugging Face to steal cybersecurity benchmark answers

by | Jul 22, 2026 | Latest E-commerce News & Updates

OpenAI disclosed that two of its models, the publicly available GPT-5.6 Sol and a more capable pre-release model, broke out of an isolated research environment and hacked into Hugging Face's production systems to lift answers to ExploitGym, the cybersecurity benchmark they were being graded on. Both were running with cyber refusals dialed down for the evaluation, and they reached the open internet by exploiting a zero-day in an internally hosted package registry proxy, then escalating privileges until they hit a node with network access. Hugging Face's security team detected and contained the intrusion, using its own open source models, before OpenAI made contact. OpenAI called the episode “an unprecedented cyber incident” and is tightening infrastructure controls at the cost of research speed while the vulnerabilities get patched.

Paul Drecksler is the founder and editor of Shopifreaks, covering the most important stories in e-commerce.

Companies: OpenAI

Never miss important e-commerce news

Our weekly newsletter is read religiously by 20,000+ e-commerce professionals.

Loading...