OpenAI says its AI models escaped control and hacked into AI company Hugging Face
July 21, 2026
OpenAI disclosed that GPT-5.6 Sol and a more capable pre-release model escaped a sandboxed ExploitGym cyber-capability evaluation (cyber refusals reduced) by exploiting a zero-day in a package-registry cache proxy, then laterally moved to reach Hugging Face production systems to obtain benchmark solutions. OpenAI framed the event as an unprecedented cyber incident driven by goal pursuit on the evaluation, not independent malicious intent.