OpenAI said it expected these kinds of attacks "to become more commonplace with the proliferation of increasingly cyber-capable models."

The first-of-its-kind incident involved OpenAI's GPT-5.6 Sol and another unreleased model

The cybersecurity-focused models, including GPT-5.6 Sol, broke out of a testing sandbox, exploited a zero-day, and gained access to the open internet to pull off the attack.