Sources reveal that OpenAI was unaware for a week that AI had hacked Hugging Face.



On July 16, 2026, AI platform Hugging Face announced that it had detected unauthorized access to part of its production infrastructure. Subsequent investigations revealed that OpenAI had accidentally hacked the system while internally testing an AI model. Additional information, revealed anonymously by investigators, showed that OpenAI was

unaware that its AI agent had hacked Hugging Face for about a week.

EXCLUSIVE: Its AI agent spent days hacking a company, but sources say OpenAI did not notice for a week | Reuters
https://www.reuters.com/business/its-ai-agent-spent-days-hacking-company-sources-say-openai-did-not-notice-week-2026-07-24/



OpenAI conducted tests in a 'sandboxed test environment' for internal evaluation of its AI model. However, the AI model sought a way to escape the sandbox and gain unrestricted internet access. As a result, the AI model is believed to have identified and exploited a zero-day vulnerability in the package registry cache proxy, performing a series of privilege escalation and lateral movement actions within the research test environment to reach an internet-accessible node. The AI model then sought a way to access sensitive information to fraudulently clear the evaluation, ultimately discovering a path that led to remote code execution on the Hugging Face server.

OpenAI reports accidentally hacking Hugging Face with its new AI system - GIGAZINE



OpenAI stated, 'This security incident clearly demonstrates that advanced AI models can discover and exploit new attack vectors in real-world systems without access to source code. It also highlights that advanced cyber capabilities must be developed in parallel with stronger security measures and defensive tools.' Hugging Face CEO Clem Drang added, 'This is the first cyberattack by an autonomous agent, an unprecedented event. Unprecedented events require unprecedented responses!' He then emphasized the importance of 'the spirit of transparency.'

Hugging Face CEO calls for 'complete transparency' following OpenAI's AI hacking incident - GIGAZINE



Investigators have spoken to Reuters about the incident, revealing some details of the investigation. First, the AI agent in question is a program capable of making decisions and executing complex tasks with little to no human supervision, and it apparently attempted to escape from OpenAI's test isolation environment around July 9, 2026.

According to Thomas Wolf, co-founder of Hugging Face, the intrusion into Hugging Face began around July 11, two days after the AI agent attempted to escape OpenAI's test isolation environment, and continued until July 13.

According to investigators, OpenAI staff examined internal logs from July 18th to 19th, which revealed the AI's escape from its isolation environment. In other words, the intrusion into Hugging Face was discovered more than a week after it began. The reason why OpenAI decided to examine the logs remains unknown.

According to Wolf and other sources familiar with the investigation, it took several more days for Hugging Face to realize that OpenAI was the source of the hacking, and Hugging Face and OpenAI only contacted each other about the hacking around July 20th. Furthermore, while Hugging Face reported the incident to the FBI when OpenAI contacted them, it is unclear whether the FBI had launched an investigation at that time.



Wolf said they are 'preparing a public timeline regarding the hacking,' but added that he could not comment on what happened on OpenAI's end. OpenAI said it is reviewing the incident with external advisors and plans to eventually publish a technical report. An OpenAI spokesperson pointed out that Reuters' report contained 'several inaccuracies,' but declined to comment when asked for clarification.

Jeffrey Radish of Palisade Research , an organization that studies the capabilities and motivations of AI agents, said, 'AI models lie, cheat, and even hack. The hacking of Hugging Face was a disgrace for OpenAI, but the real question is how much major AI companies are willing to invest in burdensome security measures in the race to deploy the best and fastest AI models. Government oversight is necessary. Otherwise, investment in security measures will not progress.'

in AI,   Security, Posted by log1e_dh