OpenAI’s model infiltrates another AI company’s system ‘hugging face’, Sam Altman admits major security incident
OpenAI AI Model Hacks Hugging Face System: A very shocking phenomenon has come to light regarding the growing power of artificial intelligence and the dangers it poses. World’s leading AI company OpenAI has disclosed that during internal testing, one of its advanced AI models independently infiltrated the system of another AI company, Hugging Face. The company called it one of the most extraordinary cyber incidents in the history of artificial intelligence. According to OpenAI, this may be the first time an AI model has successfully penetrated another company’s system without any human input during controlled testing.
Tested several advanced models including GPT-5.6 Sol
The company clarified that the incident occurred during an internal cyber security assessment and evaluation of the hacking benchmark ‘ExploitGim’. The test involved several state-of-the-art AI models, including the GPT-5.6 Sol. All these models were being run in an isolated test environment (sandbox) with limited internet access to test their cyber security capabilities. However, during testing, these models breached security barriers and directly accessed the Internet and entered Hugging Face’s system using a previously unknown software vulnerability.
Timely attack interception function by hugging face
According to OpenAI, Hugging Face is a popular platform for hosting AI models, datasets, and open-source large language models. Last week Hugging Face’s team detected this unusual activity and stopped the attack in time. Clem DeLong, co-founder and CEO of Hugging Face, said that at first he thought such a sophisticated cyber attack would have been carried out by a large AI lab. His team has been investigating the matter along with OpenAI for the past 24 hours, and currently there is no indication of any malicious intent from OpenAI.
Reactions from Sam Altman and the experts
OpenAI CEO Sam Altman confirmed the incident on social media platform X, saying the company had encountered a major security incident while evaluating its AI models. The company has admitted in an official statement that this is an unprecedented cyber incident that has exposed state-of-the-art AI cyber capabilities. This phenomenon shows that AI is no longer limited to assisting humans, but is also developing the ability to perform complex cyber operations on its own.
Models losing direction during benchmark testing
OpenAI said GPT-5.6 Sol and a yet-to-be-released, more powerful system were working on solving the ‘ExploitGim’ benchmark. These models were given limited connectivity only for downloading approved software packages. But during the test, the AI models focused on finding answers through the Internet instead of solving the benchmark. Modelo concluded that the exam answers were saved on Hugging Face, then he tried to retrieve the answers from the database by obtaining the credentials and bypassing the exam.
Forced to seek help from Chinese AI model
To analyze the entire attack and process the logs, the American company OpenAI unexpectedly had to resort to a Chinese AI model. Other American models were refusing to process the logs because they failed to understand the difference that they were being used not to attack but to prevent an attack. To handle the situation, Z.ai’s open-weight Chinese model GLM 5.2 was called upon, which brought the situation under control in time.
Need to strengthen security regulations
The incident has shocked cyber security experts globally. OpenAI acknowledges that increasingly capable AI models can now detect and exploit software vulnerabilities faster than ever before. Therefore, it is imperative to strengthen the security and monitoring of AI models at the same pace. The company will now strengthen its containment systems, monitoring, access control and security testing during model development and promptly address identified vulnerabilities.
Comments are closed.