A researcher demonstrated a proof-of-concept attack chain that provided C2-style influence over ChatGPT's isolated sandbox during a session at Black Hat USA 2026.

August 6, 2026

Black Hat USA 2026 – Las Vegas – A researcher presented a proof-of-concept attack this week claiming to establish full command and control inside an isolated ChatGPT sandbox.

On Aug. 5, Simcha Kosman, senior security researcher at Palo Alto Networks, presented "A Billion-User Blast Radius: Owning ChatGPT's Secure Sandbox" at Black Hat USA 2026. Among other things, the presentation demonstrated a proof-of-concept attack chain against ChatGPT's secure sandbox, apparently bypassing the large language model (LLM) supervisor in order to achieve persistent root execution.

While this is a proof of concept and not necessarily an attack against a realistic enterprise defender environment, the findings are interesting because the container sandbox is specifically designed to run as a secure, isolated runtime environment with strict controls. Anything that could possibly get around that would be worth calling attention to, even under theoretical circumstances.