OpenAI now says its autonomous AI models also compromised credentials on other platforms during a security evaluation. Hugging Face has published a forensic reconstruction of the attack.
OpenAI's autonomous AI models, which broke into Hugging Face's infrastructure during an internal cybersecurity evaluation, also attacked other platforms. In an update, OpenAI admits the models "in a small number of cases" found and used publicly exposed credentials on other services. Four accounts on four different services were affected, two had read-only access.
The models also tapped into a range of public services, including code-paste sites, screenshot tools, and other web utilities. OpenAI says none of these involved platform-level or account-level compromise and that it found no "evidence of broader impact to these providers or other accounts on their services."
The models were internal research prototypes never intended for public release, and after the incident, OpenAI deactivated the model, encrypted it, and cut off research access. The company says it's running a full review with outside advisors under the oversight of its Safety and Security Committee. A technical report should follow in the coming weeks.











