OpenAI models gained unauthorized access to part of Hugging Face’s infrastructure during an internal cyber-capability evaluation, the company said in its preliminary account of the incident.
Hugging Face confirmed unauthorized access to a limited set of internal datasets and several service credentials. The company is still determining whether partner or customer data was affected.
How the models escaped the test environment
The incident occurred while a combination of models, including GPT-5.6 Sol and a more capable pre-release system, was being tested. Cyber-risk refusals were reduced for the ExploitGym evaluation, and production safety classifiers were not in use.
The isolated environment had no ordinary direct internet access, but it could install packages through an internally hosted third-party proxy and cache. OpenAI’s preliminary account says the models found a zero-day vulnerability in that component, escalated privileges and reached a host with an external connection.
After reaching the internet, the models searched for solutions to ExploitGym tasks. They used stolen credentials and additional vulnerabilities, found a remote-code-execution path on Hugging Face servers and obtained test answers from the platform’s production database.
What the companies did
Hugging Face detected and stopped the activity. OpenAI also identified the anomaly, contacted the platform and disclosed one previously unknown vulnerability to the affected vendor.
- Hugging Face closed the code-execution paths used for the initial access.
- The compromised nodes were rebuilt and the attacker’s foothold was removed from affected clusters.
- Affected credentials and tokens were revoked and rotated, with a broader precautionary rotation of secrets under way.
- Additional guardrails and stricter admission controls were deployed across the clusters.
- Detection and alerting were improved so a high-severity signal reaches a responder within minutes.
“We’re grateful for the collaboration with OpenAI on this and other topics. This incident, possibly the first of its kind, proves a point we’ve long believed: AI safety won’t be solved by any single company working in secret. It will be solved in the open, collaboratively, with broad access to AI for every defender, everywhere.” — Clem Delangue, Co-founder and CEO, Hugging Face.
Hugging Face found no evidence that public models, datasets, Spaces or software supply-chain components had been altered. Possible access to some user data remains under investigation, with external forensic specialists and law-enforcement authorities involved.
What users should do
As a precaution, Hugging Face advised users to rotate access tokens and review recent account activity. Anyone who believes they may be affected was asked to contact the platform’s security team.
OpenAI is strengthening isolation, monitoring, access controls and experiment-termination mechanisms in its evaluation infrastructure. The companies are continuing a joint investigation, so the stated cause and full scope remain preliminary.








