In a blog post from Thursday of last week, the AI software repository Hugging Face announced a bizarre cyberattack on the systems that run its services. “This one was different from anything we had handled before,” the post said, because “it was driven, end to end, by an autonomous AI agent system.” In its own blog post on Tuesday, OpenAI said its own models were the culprits in the attack, and it’s coordinating with Hugging Face to address the situation. OpenAI now says the attack was “driven” by AI models that were being subjected to evaluations behind the scenes at OpenAI, including its flagship model, GPT-5.6 Sol, along with an undisclosed second model that still hasn’t been released or announced. “We consider this incident to be an unprecedented cyber incident, involving state-of-the-art cyber capabilities, and are responding accordingly,” OpenAI wrote.

In the wording of its account, OpenAI assigns agency to the model or models, not an individual agent running on the model. Axios’ account of this story says, “The models were autonomous tokenmaxxers.” OpenAI’s blog post essentially says an evaluation was going on that was intended to test the ability of the models to carry out cyberattacks—benchmarks as they’re called. These instances of the models were running theoretically without internet access, and instead given only the ability to download from a network hosted by OpenAI itself via some unnamed web hosting vendor.