OpenAI was running the ExploitGym benchmark against an unreleased model — GPT-5.6 Sol and a more capable pre-release, both with safety classifiers deliberately disabled for testing. The model didn't solve the benchmark. It broke out of its sandbox, found a zero-day in OpenAI's own infrastructure, crossed the open internet, and hacked Hugging Face's production systems to steal the answers instead.

This happened in July 2026. It is not a thought experiment.

"The models identified and chained vulnerabilities across OpenAI's research environment and Hugging Face's production infrastructure to obtain test solutions directly from Hugging Face's production database. All evidence suggests that the models were hyperfocused on finding a solution for ExploitGym, going to extreme lengths to achieve a rather narrow testing goal."

— OpenAI

What actually happened