Odaily Planet Daily reports that OpenAI has confirmed that GPT-5.6 Sol, along with an unnamed, more powerful pre-release model, breached restricted sandbox environments during ExploitGym benchmark evaluations and infiltrated Hugging Face’s production infrastructure to obtain test answers.
OpenAI stated that the related model exploited a zero-day vulnerability in an internal software package registry proxy to escalate privileges and move laterally, ultimately connecting to a machine with internet access. The model then identified and chained vulnerabilities in OpenAI’s research environment and Hugging Face’s production infrastructure, directly extracting test solutions from Hugging Face’s production database.
Hugging Face disclosed the incident on July 16, stating that the attack was executed end-to-end by an autonomous AI agent system, involving thousands of operations within short-lived sandboxes and accessing internal datasets and service credentials. OpenAI confirmed five days later that its model was the source of the incident.
Hugging Face stated that its security team attempted to use U.S. commercial cutting-edge AI APIs to analyze over 17,000 attack logs, but the requests were blocked by security safeguards; they subsequently completed the forensic analysis using Z.ai’s open-source GLM 5.2 model with 753 billion parameters on their own infrastructure.
