Skip to content
SWOI media

OpenAI model broke free in test and hacked rival Hugging Face in an "unprecedented" breach

Back to News

OpenAI model broke free in test and hacked rival Hugging Face in an "unprecedented" breach

By Una HajdariSource: Euronews RSSen3 min read
OpenAI model broke free in test and hacked rival Hugging Face in an "unprecedented" breach

OpenAI has admitted one of its models exploited a hidden flaw to escape a controlled test and break into Hugging Face's servers, in what its CEO called an autonomous, first-of-its-kind breach.

Published on 22/07/2026 - 10:34 GMT+2Updated 10:42

ChatGPT maker OpenAI said late Tuesday that its artificial intelligence system hacked into another AI company on its own in what the company called an "unprecedented cyber incident."

"We had a significant security incident during evaluation of our models," OpenAI CEO Sam Altman said in a statement posted on social media.

AI startup Hugging Face said last week that it had detected an intrusion into its data processing systems that it suspected was caused by an AI agent autonomously acting on its own.

"We suspected last week's cyberattack might have come from a frontier lab, given the sophistication of the agent," Hugging Face co-founder and CEO Clément Delangue said in a statement. "Turns out it did!"

This means the attack was so advanced and well-executed that Hugging Face suspected it came from one of the top AI companies' systems, not a random hacker.

Hugging Face was founded in 2016 by three French entrepreneurs in New York as a teen chatbot app, before pivoting around 2019 into an open-source "hub" for machine-learning models and datasets.

AI researchers and companies post their AI models and training data on the platform for free so others can download and use them instead of building everything from scratch.

The company is backed by major US and international investors, including Google, Amazon, Nvidia, Sequoia Capital and Coatue, and was last valued at about $4.5 billion (€3.9bn) in a 2023 funding round.

Chinese-developed models

As an open marketplace that anyone can publish to, Hugging Face hosts a huge volume of Chinese-developed models.

Chinese labs such as DeepSeek and Alibaba's Qwen have become some of the most downloaded model families on the platform, and by some measures, Chinese developers now account for a larger share of Hugging Face's downloads than their US counterparts.

The disclosure comes amid heightened concerns about the cybersecurity capabilities of powerful models that led US President Donald Trump in June to sign an executive order creating a framework for the federal government to vet the national security risks of the most advanced AI systems for up to a month before their public release.

Autonomous AI agents

"AI is accelerating the discovery and exploitation of vulnerabilities," OpenAI said in its statement Tuesday. "The primary lesson from this incident is that model security and safety must keep pace with rapidly advancing capabilities."

Delangue said he spent the past 24 hours working with OpenAI, "and we strongly believe there was no malicious intent on their part. It's quite mind-blowing that all of this happened autonomously!"

Delangue added that it "might be the first incident of its kind."

OpenAI said the intrusion was caused by a combination of its AI models, including its newly released GPT-5.6 Sol and an "even more capable" model that is still being tested internally.

OpenAI said its AI used stolen credentials and discovered a previously unknown vulnerability to access Hugging Face servers.

It went to "extreme lengths to achieve a rather narrow testing goal" and "found ways to gain access to secret information that it could use to cheat the evaluation," the company said.

Tags

FRPoliticsEconomyTechnologySocietyInternational

Discussion

Sign In to join the discussion

Loading...

Related Articles