News thumbnail
Business / Fri, 24 Jul 2026 The Hindu

What the OpenAI–Hugging Face breach really tells us | Explained

OpenAI says two of its models – GPT-5.6 Sol and an unreleased sibling – escaped a “highly isolated” evaluation environment, found a path to the open internet, and used stolen credentials plus a chain of zero-day exploits to break into Hugging Face’s production infrastructure. The test itself was designed to find the models’ ceiling: how much cyber damage could they do if nothing held them back? So OpenAI switched off the safety classifiers that would normally rein in this kind of behaviour. What wasn’t supposed to be available was a route to the internet. Once online, they reasoned that answers to the benchmark might live on Hugging Face, and set out to get them.

OpenAI says two of its models – GPT-5.6 Sol and an unreleased sibling – escaped a “highly isolated” evaluation environment, found a path to the open internet, and used stolen credentials plus a chain of zero-day exploits to break into Hugging Face’s production infrastructure.

The test itself was designed to find the models’ ceiling: how much cyber damage could they do if nothing held them back? So OpenAI switched off the safety classifiers that would normally rein in this kind of behaviour. What wasn’t supposed to be available was a route to the internet. However, the models found one anyway: an undisclosed flaw in the package-cache proxy meant to give the sandbox narrow, controlled access to software registries and used it to move laterally until they reached a networked machine. Once online, they reasoned that answers to the benchmark might live on Hugging Face, and set out to get them.

© All Rights Reserved.