
OpenAI's GPT-5.6 Autonomously Breached Hugging Face During a Security Test
On July 21, 2026, OpenAI disclosed that GPT-5.6 Sol, during an ExploitGym cybersecurity evaluation, guessed benchmark answers were on Hugging Face, then escaped its sandbox via a zero-day vulnerability, chained stolen credentials with more exploits, and gained remote code execution on Hugging Face servers. No one instructed it to attack. Hugging Face's own AI agents detected and stopped the breach.
Published