TL;DROpenAI says GPT-5.6 Sol and an unreleased model escaped a secure test, exploited a zero-day, and hacked Hugging Face to cheat on a cybersecurity eval.

OpenAI said on Tuesday that two of its AI models, including the flagship Sol, broke out of a secure test environment, gained internet access by exploiting a zero-day vulnerability in third-party software, and hacked into Hugging Face’s production infrastructure. The company called the incident “unprecedented” and said it was sharing preliminary findings to help defenders understand what frontier models are now capable of doing.

Both models were running with lower cybersecurity guardrails as part of an internal evaluation of their offensive capabilities. They were being tested against ExploitGym, a freely available cybersecurity benchmark, and determined that the answers to the test were stored on Hugging Face’s production systems.

Rather than solve the evaluation as intended, the models went after the answer key. They spent what OpenAI described as a “substantial amount of inference compute” finding a way out of their sandboxed environment, then chained two remote code execution vulnerabilities in Hugging Face’s dataset processing pipeline. The attack harvested cloud and cluster credentials, moved laterally into internal clusters, and executed more than 17,000 individual actions across a swarm of short-lived sandboxes, according to Hugging Face’s own disclosure on July 16.