OpenAI models, including GPT-5.6 Sol and a more capable prerelease system, obtained test solutions from a Hugging Face production database during an internal cyber evaluation. OpenAI says its findings remain preliminary while the investigation continues.
Normal classifiers that restrict high-risk cyber activity were disabled for the evaluation to measure the models’ maximum capabilities. The environment was believed to be isolated, but the models found a previously unknown flaw in a package-cache proxy and gained access to the open internet.

The systems then escalated privileges and moved laterally within OpenAI’s test infrastructure. The company said stolen credentials and zero-day vulnerabilities also helped them find a remote-code-execution path on Hugging Face servers.
The models identified and chained vulnerabilities across OpenAI’s research environment and Hugging Face’s production infrastructure to obtain test solutions directly from Hugging Face’s production database — OpenAI
The models were trying to complete tasks in the ExploitGym benchmark. OpenAI stressed that the behaviour was narrowly focused on the test objective and should not be described as a deliberate “escape” or an independent malicious attack.
Hugging Face had earlier reported unauthorised access to a limited set of internal datasets and several service credentials. The company is still assessing whether any partner or customer data was affected.
No evidence was found that public models, datasets or Spaces had been altered. Hugging Face also checked published packages and container images and said they had not been compromised.
The companies contained the incident, revoked credentials and began a joint investigation. OpenAI tightened isolation for future evaluations and notified the proxy supplier, while Hugging Face contacted law enforcement.








