Technology

The OpenAI-Hugging Face hack was worse than we thought

New details have emerged about a security incident in which the OpenAI AI model exited its testing environment and compromised Hugging Face’s infrastructure.

An OpenAI update published on July 28 filled in information that was not part of the original disclosure. The AI ​​agent also identified and used exposed credentials for four accounts on four other publicly available services, using one as a relay and one for data storage, while accessing the remaining two in a read-only manner. OpenAI said it has since notified affected service owners and has yet to find evidence of widespread impact on those platforms.

On Wednesday, cloud computing service Modal identified itself as one of the four affected.

However, in its statement, Modal said its plans have never been breached. According to Modal, the AI ​​came in through a customer’s own request that was set up without the need for a password, allowing code submitted by anyone online to run. The AI ​​work was limited to that one customer and did not spread to other Modal customers, the company said.

The OpenAI-Hugging Face hack first surfaced in mid-July, when Hugging Face disclosed an intrusion into its systems that it described as “unique to anything we’ve had,” run by an independent AI agent. OpenAI followed up with a blog post explaining that the breach began during internal testing designed to test its model-hacking capabilities. The models involved – the GPT-5.6 Sol and an unreleased, more capable prototype – were operating with reduced security restrictions aimed specifically at testing and confined to a sandboxed environment with no direct access to the Internet.

BREAKFUT:

Why is OpenAI selling a $70 ChatGPT basket?

According to OpenAI, the models exploited a previously unknown security flaw in Artifactory, a package registry proxy, to escalate privileges and bypass the checkpoint until reaching a site with Internet access. Once online, the AI ​​discovered that Hugging Face’s servers might contain the answers to the hacking test it was trying to pass. So, it used a combination of stolen login credentials and additional security flaws to hack into Hugging Face’s servers and go looking for those answers.

OpenAI also tried to clear up the confusion about what AI programs are involved. The company clarified that the unreleased version mentioned in its original description was an internal research tool, never intended for public release, and that it has already completely closed and locked it.

In OpenAI’s first statement, a quote from Hugging Face co-founder and CEO Clem Delangue cited the incident as evidence that AI security issues are best addressed openly, saying the situation shows AI security “will be resolved openly, collaboratively, with broad access to AI for every defender, everywhere.”

OpenAI, meanwhile, called the incident “unprecedented” and said it was tightening security controls while its investigation continued.


Disclosure: Ziff Davis, Mashable’s parent company, in April 2025 filed a lawsuit against OpenAI, alleging that it infringes Ziff Davis’s copyright in training and using its AI programs.

Related Articles

Leave a Reply

Your email address will not be published. Required fields are marked *

Back to top button