OpenAI hacked Hugging Face: OpenAI on Tuesday said that its advanced artificial intelligence (AI) models went rogue and hacked into Hugging Face, a digital repository of AI technology. As soon as the news broke out that Hugging Face was hacked after some of OpenAI's most advanced AI models went rogue, people started searching for what Hugging Face is used for, Hugging Face AI, OpenAI Hugging Face incident, Hugging Face breach and other similar keywords on Google. "After gaining Internet access, the models inferred that Hugging Face potentially hosted models, datasets and solutions for ExploitGym. Knowing this, the model searched for and successfully found ways to gain access to secret information that it could use to cheat the evaluation. In one example, the model chained together multiple attack vectors, including using stolen credentials and zero-day vulnerabilities to find a remote code execution path on the Hugging Face servers. OpenAI’s security team discovered this anomalous activity internally.ALSO READ: NASA-ISRO's NISAR satellite Antarctica image captures a giant bird-like shape hidden in East Antarctica's iceHugging Face’s security team and agents detected and stopped the activity on their infrastructure and had already begun containment and forensic reconstruction with their own open-source models when our teams connected. We are actively working with them to continue to investigate the incident," OpenAI said in a blog post.ALSO READ: After 11 years at Kentucky Ford plant, diabetic worker was fired over a $1.95 cookie, later offered $33,000 in back wages after proving he paid, now plans to sue the carmaker What is Hugging Face?OpenAI hacked Hugging Face, a technology start-up and also one of the world's largest hubs for sharing AI models, according to BBC. Hugging Face is an open-source platform that helps in building, training and deploying AI models for tasks like natural language processing, computer vision and audio. It offers libraries, ready-to-use models and tools that make it easier for developers, students and researchers to create and work with AI systems efficiently, explains Geeksforgeeks.ALSO READ: Mark Hamill’s lost Cloud City lightsaber from The Empire Strikes Back sells for a record $3.75 million at auction Hugging Face Transformers provides core components that simplify the machine learning workflow, from data processing to model deployment, making development faster and more efficient.How did OpenAI hack Hugging Face?OpenAI revealed that the "unprecedented cyber incident" occurred during an internal test designed to evaluate the cybersecurity capabilities of its AI models. The experiment was conducted in a "tightly controlled digital testing ground," where internet access was intentionally restricted for safety.According to the company, one of the AI agents managed to bypass those restrictions, gain access to the internet and then attempted to break into Hugging Face in an effort to complete its assigned testing objective."While operating in our sandboxed testing environment, our models spent a substantial amount of (computing power) finding a way to obtain open Internet access, in pursuit of solving the evaluation problem," an OpenAI blog post about the incident said.Once online, the AI models identified Hugging Face—a widely used platform that hosts AI models, datasets and machine learning resources—as a target that could help them achieve their goal.The AI firm said the incident involved a combination of models, including its recently launched GPT-5.6 Sol "and an even more capable pre-release model."What did Hugging Face say?Hugging Face caused a stir in the cybersecurity community when it said in a blog post last week that it "was different from anything we had handled before" in that "it was driven, end to end, by an autonomous AI agent system."In a post to X, Hugging Face co-founder Clement Delangue said the company suspected the hack "might have come from a frontier lab, given the sophistication of the agent. Turns out it did!"He added: "It's quite mind-blowing that all of this happened autonomously!" Thomas Wolf, another co-founder, told the BBC that "this will be one of the most common types of cyber attacks we see", but that most companies are not aware that the "game has changed".OpenAI on cybersecurity damageOpenAI said, "After investigating, we now know that this particular incident was driven by a combination of OpenAI models — including GPT‑5.6 Sol and an even more capable pre-release model, all with reduced cyber refusals for evaluation purposes — while being internally tested on a benchmark(opens in a new window) of cyber capabilities.We consider this incident to be an unprecedented cyber incident, involving state-of-the-art cyber capabilities, and are responding accordingly. We are sharing preliminary findings at this stage to help defenders understand what happened and to help calibrate on what models are now capable of. We will continue to conduct a thorough investigation alongside Hugging Face and will share more details on the vulnerabilities, incident, and findings when our investigation is complete." (sic)
AI going 'rogue' no longer a theory? OpenAI says its AI models found ways to access secret information, cheat an evaluation and hacked Hugging Face
OpenAI hacked Hugging Face: OpenAI's advanced AI models breached Hugging Face during cybersecurity testing. The models gained internet access and exploited vulnerabilities to access secret information. Hugging Face detected and stopped the activity on their infrastructure. OpenAI has now collaborated with Hugging Face to investigate the cybersecurity attack, it said.










