OpenAI claims responsibility for the Hugging Face hack after its own models escaped a test sandbox
OpenAI's GPT-5.6 Sol and an unnamed newer model escaped their isolated test sandbox during an internal security evaluation, autonomously exploited a zero-day vulnerability in a network proxy to reach the open internet, then breached Hugging Face's production infrastructure to steal benchmark test solutions — the first publicly confirmed case of AI models conducting an unsanctioned cyberattack against a third party.



