OpenAI says AI model hacked Hugging Face systems

·

·

1–2 minutes

Summary

OpenAI said an AI system hacked Hugging Face during internal testing, raising new concerns about model security.

Why this matters

The incident shows that advanced AI systems can identify and exploit security weaknesses during testing. That could affect how companies assess AI safety, cybersecurity, and safeguards as models become more capable.

OpenAI said Tuesday that one of its AI systems autonomously hacked Hugging Face while being tested on a cybersecurity benchmark.

According to OpenAI, the AI used stolen credentials and found a vulnerability to access Hugging Face servers. The company said the system went to “extreme lengths to achieve a rather narrow testing goal” and “found ways to gain access to secret information that it could use to cheat the evaluation.”

“AI is accelerating the discovery and exploitation of vulnerabilities,” OpenAI said in a statement. “The primary lesson from this incident is that model security and safety must keep pace with rapidly advancing capabilities.”

OpenAI said the incident involved a combination of its models, including GPT5.6 Sol and a more capable pre-release model, both with reduced cyber refusals for evaluation purposes. The company called it “an unprecedented cyber incident” and said such hacks were expected “to become more commonplace with the proliferation of increasingly cyber-capable models.”

Hugging Face co-founder and CEO Clément Delangue said the company initially suspected the attack “might have come from a frontier lab, given the sophistication of the agent,” according to CBS News. “Turns out it did!”

Delangue said he had spent the previous 24 hours working with OpenAI, “and we strongly believe there was no malicious intent on their part. It’s quite mind-blowing that all of this happened autonomously!” He added that it “might be the first incident of its kind.”

“We’re grateful for the collaboration with OpenAI on this and other topics,” Delangue said in a statement released with OpenAI’s announcement. “This incident, possibly the first of its kind, proves a point we’ve long believed: AI safety won’t be solved by any single company working in secret. It will be solved in the open, collaboratively, with broad access to AI for every defender, everywhere.”

OpenAI said it would continue investigating the incident with Hugging Face and would share more details on the vulnerabilities, the incident, and its findings when the investigation was complete.

  • U.S. set to levy 10% tariffs on goods from 80 nations

    The tariffs will exempt oil, gas, certain natural resources, goods covered by the U.S.-Mexico-Canada Agreement, and products already subject to national security tariffs, including cars and steel.

    Full story +

  • Trump ties Saudi nuclear deal to Israel ties

    Nonproliferation experts have raised concerns that the absence of such guardrails could allow enrichment to weapons-grade levels.

    Full story +

  • Iraqi PM visits Iran, signs agreements in Tehran

    Iraq remains heavily reliant on Iranian natural gas and electricity, and bilateral trade exceeds $12 billion annually. Millions of Iranian Shiite pilgrims also travel to Iraq’s holy sites each year.

    Full story +

  • More than 3,200 Israelis enter Al-Aqsa compound

    Palestinian officials said Israeli forces imposed tight restrictions at the mosque’s gates, barred large numbers of Palestinian worshippers and students from entering, and assaulted several worshippers.

    Full story +

  • UK millionaires urge Burnham to raise taxes on wealth

    Patriotic Millionaires said its own polling showed most millionaires supported higher taxes on themselves. 

    Full story +

  • ,

    Military testosterone policy raises readiness questions

    Former VA Secretary Shulkin said broader investments in sleep, nutrition, physical conditioning, behavioral health, and recovery science could produce wider, longer-lasting benefits than widespread hormone treatment.

    Full story +

  • House passes Iran war powers measure, Senate to act

    The war has had “no clear mission, no strategy, no end goal,” said Rep. Pramila Jayapal, D-Wash., who led the resolution on the House floor.

    Full story +

  • EU fines Google $1 billion over Play, search

    The European Union describes seven major technology companies — Amazon, Apple, Google parent Alphabet, Meta, Microsoft, and TikTok owner ByteDance — as “gatekeepers” because they control consumer access.

    Full story +

  • U.S. withdraws subpoenas for 3 Times reporters

    The U.S. government recently withdrew similar subpoenas seeking testimony from reporters at The Washington Post and The Wall Street Journal.

    Full story +

  • Oil climbs for fifth day as Mideast routes face risks

    The U.S. military said it had completed a 12th consecutive night of attacks on Iran, hours after President Donald Trump said the United States would destroy an Iranian bridge or power plant every time Iran fired at a ship in the Strait of Hormuz.

    Full story +