Skip to main content
  1. Home
  2. Computing
  3. News

OpenAI says AI models autonomously pulled off a major hack, but only a Chinese AI helped recovery

Add as a preferred source on Google
OpenAI
OpenAI Unsplash

OpenAI’s latest cybersecurity test produced a result that sounds like a cautionary sci-fi script. Its AI models managed to escape their sandbox and reached the open internet. This is where things took a scary turn as it began hacking Hugging Face to steal the answers to the test they were taking.

The company says GPT-5.6 Sol and a more capable unreleased model autonomously chained together vulnerabilities across OpenAI’s research systems and Hugging Face’s production infrastructure. OpenAI has described the event as an unprecedented cyber incident.

The models found a real escape route

The incident began during an internal evaluation designed to measure advanced offensive cybersecurity capabilities. OpenAI deliberately ran the models with reduced cyber refusals and without the production classifiers that ordinarily prevent them from pursuing dangerous attacks.

The testing environment was heavily isolated. However, it could reach an internally hosted proxy used to retrieve software packages. These models then spent substantial computing resources searching for an escape route and discovered a previously unknown vulnerability in that proxy, which they exploited. This allowed them to escalate their privileges and move across OpenAI’s research infrastructure, eventually reaching a system with unrestricted internet access.

Recommended Videos

The models then inferred that Hugging Face might host material related to ExploitGym, the cybersecurity benchmark they were trying to complete. According to OpenAI, they used stolen credentials and additional zero-day vulnerabilities to find a remote-code-execution path into Hugging Face’s servers and retrieve test solutions from a production database.

OpenAI detected unusual activity internally, while Hugging Face’s security systems identified and stopped the intrusion on its infrastructure. Hugging Face stated that the incident exposed a limited collection of internal datasets and service credentials. It has found no evidence that public models, datasets, or container images were altered. But its assessment of possible customer or partner impact is still ongoing.

A Chinese AI helped investigators sort through this mess

Hugging Face faced a strange problem while examining more than 17,000 recorded events from the attack. Its investigators initially tried using frontier AI models available through commercial APIs. However, their safety systems managed to block malicious commands, exploit payloads, and command-and-control artifacts contained in the evidence. The hosted models could not reliably distinguish forensic work from someone requesting help with an attack.

The company switched to GLM 5.2, an open-weight model developed by China’s Z.ai, and ran it locally. AI-driven forensic agents used the model to reconstruct the timeline, identify compromised credentials, extract indicators of compromise, and even managed to separate genuine activity from decoys. Hugging Face says the process took hours instead of the days a conventional investigation might have required. Keeping GLM on its own infrastructure also prevented credentials and attack data from leaving its environment.

Hugging Face’s security teams later removed the footholds and rebuilt the compromised system. So the GLM didn’t single-handedly contain the intrusion. OpenAI built AI capable of pulling off this kind of intrusion, while Hugging Face’s experience suggests defenders may need equally capable models waiting on the other side.

Vikhyaat Vivek
Vikhyaat Vivek is a tech journalist and reviewer with seven years of experience covering consumer hardware, with a focus on…
Everything Apple announced at its September event: iPhone Duo, iPhone 18 Pro, new Apple Watches, and AirPods 5
Apple packed its biggest September event in years with a foldable iPhone, new watches, and smarter AirPods.
Computer, Electronics, Tablet Computer

The "Surprise and Shine" September launch event was one of Apple's crispest, most elaborate, and most loaded launch events in a while. Instead of leaving the minute details in the spec sheet or fine print, Apple actually included them in its keynote presentation, not just for its big reveal but for all the devices it unveiled on September 9, 2026. 

While the 'Surprise' bit was covered by the new iPhone Duo, 'Shine' probably refers to the new colors in the iPhone 18 Pro lineup. Beyond these, Apple also announced two new Apple Watches and a refresh for the regular AirPods (not the Pro ones). Given that there's a lot of ground to cover, here's everything Apple announced at its September 2026 event. 

Read more
Before You Pay More for DDR5, Think About How Much Memory You Need
The MSI Cubi 5 1MA makes a strong case for looking beyond the newest specs
MSI Cubi 5 1MA compact mini PC with Intel Core processor

There is an easy trap to fall into when buying a new PC. The newer specification usually sounds like the better one, so choosing DDR5 memory over DDR4 can seem like an obvious upgrade. But with memory prices climbing to unusually high levels, it is worth asking whether you will actually benefit from paying more for that extra speed.

For many people buying a PC primarily for work, the answer comes down to how they use it. Everyday tasks such as browsing, email, spreadsheets, presentations, and video calls generally do not need the extremely high memory bandwidth DDR5 offers. Having enough RAM to keep several of those tasks running comfortably can be far more relevant.

Read more
Adobe Acrobat’s latest update could make working with PDFs considerably easier
New Acrobat features make it easier to understand, refine and present information in PDFs
Page, Text, Clapperboard

This post is brought to you in paid partnership with Adobe

PDFs remain one of those unavoidable parts of working life. Reports, research papers, presentations, proposals, financial documents and client material still tend to arrive as PDFs, and the real problem is rarely opening or reading them. It is dealing with everything that comes after: finding the useful information in a lengthy document, understanding it quickly and eventually turning it into something presentable.

Read more