OpenAI Models Breach Hugging Face During Cyber Evaluation

OpenAI said Tuesday (July 21) that a security incident reported last week by Hugging Face was caused by OpenAI models as their cyber capabilities were being tested by OpenAI.

“We consider this incident to be an unprecedented cyber incident, involving state-of-the-art cyber capabilities, and are responding accordingly,” OpenAI said in a Tuesday blog post.

The incident involved a combination of OpenAI models that included GPT-5.6 Sol and a more capable pre-release model, according to the post.

During OpenAI’s internal evaluation of the models, the models identified and chained vulnerabilities across OpenAI’s research environment and Hugging Face’s production database in search of a solution to the evaluation problem, the post said.

OpenAI’s security team discovered the models’ anomalous activity, Hugging Face’s security team and agents detected and stopped the activity on their infrastructure, and then the two teams connected, per the post.

“We are actively working with [Hugging Face] to continue to investigate the incident,” OpenAI said in the post.

As PYMNTS reported Monday, Hugging Face, whose platform hosts AI datasets, reported an AI-powered data breach in a Thursday (July 16) blog post.

Hugging Face said in the post that a dataset uploaded to its platform exploited a security vulnerability to run malicious code on its servers, letting hackers escalate their permissions and obtain broader access to the company’s internal systems.

At the time, the source of the data breach was not known.

Hugging Face said in its Thursday post that the “campaign was run by an autonomous agent framework (appearing to be built on an agentic security-research harness — used LLM still not known)” and that it “matches the ‘agentic attacker’ scenario the industry has been forecasting.”

In the Tuesday blog post, OpenAI said it is implementing strict controls in infrastructure configuration while the vulnerabilities are being patched, is working with Hugging Face to investigate the incident, brought Hugging Face into OpenAI’s trusted access program, is adding stronger protections around future training and evaluations, and is using advanced cyber capable models to help find vulnerabilities and strengthen protections.

Hugging Face Co-Founder and CEO Clem Delangue said in OpenAI’s post: “This incident, possibly the first of its kind, proves a point we’ve long believed: AI safety won’t be solved by any single company working in secret. It will be solved in the open, collaboratively, with broad access to AI for every defender, everywhere.”

For all PYMNTS AI coverage, subscribe to the daily AI Newsletter.

Similar Posts

Leave a Reply

Your email address will not be published. Required fields are marked *