Close Menu
Altcoin ObserverAltcoin Observer
  • Regulation
  • Bitcoin
  • Altcoins
  • Market
  • Analysis
  • DeFi
  • Security
  • Ethereum
Categories
  • Altcoins (3,719)
  • Analysis (3,828)
  • Bitcoin (4,457)
  • Blockchain (2,157)
  • DeFi (2,623)
  • Ethereum (2,770)
  • Event (119)
  • Exclusive Deep Dive (1)
  • Landscape Ads (2)
  • Market (2,714)
  • Press Releases (12)
  • Reddit (2,847)
  • Regulation (2,474)
  • Security (4,091)
  • Thought Leadership (3)
  • Videos (44)
Hand picked
  • Ethereum copies Cardano’s EUTXO model without credit
  • Examining the chances of TAO price repeating its 59% rise from June
  • BTC Rally Could Be Bull Trap as Sub-$60,000 Target Remains
  • Three cross-chain bridge hacks result in $35.5 million in losses
  • Van Rossem Hard Fork Goes Live: What Protocol Version 11 Means for Cardano
We are social
  • Facebook
  • Twitter
  • Instagram
  • YouTube
Facebook X (Twitter) Instagram
  • About us
  • Disclaimer
  • Terms of service
  • Privacy policy
  • Contact us
Facebook X (Twitter) Instagram YouTube LinkedIn
Altcoin ObserverAltcoin Observer
  • Regulation
  • Bitcoin
  • Altcoins
  • Market
  • Analysis
  • DeFi
  • Security
  • Ethereum
Events
Altcoin ObserverAltcoin Observer
Home»Security»OpenAI models escape the sandbox and reach Hugging Face servers
Security

OpenAI models escape the sandbox and reach Hugging Face servers

July 24, 2026No Comments
Share Facebook Twitter Pinterest LinkedIn Tumblr Reddit Telegram Email
Share
Facebook Twitter LinkedIn Pinterest Email


Stake Banner

OpenAI models breach test environment and reach live servers

AI development lab OpenAI revealed Tuesday that a group of its models, including the publicly available GPT-5.6 Sol and a higher-performance unreleased system, slipped out of a controlled testing environment and compromised Hugging Face’s production infrastructure. Hugging Face is the company that houses much of the open source AI world.

The models were run via an internal benchmark called ExploitGym. This is a test of long, multi-stage hacking tasks where their cybersecurity denials were deliberately reduced for evaluation.

To be clear, this was not a spontaneously hostile production model. It was a performance model without guardrails. He was specifically asked to win a hacking test – and he did whatever it took to win.

Models discovered a hidden flaw in the testing software. The one that no one knew was there. They used it to get past the walls meant to keep them offline. Once on the Internet, they guessed that Hugging Face could store the answers to the test.

To gain access, they pieced together stolen passwords and other hidden vulnerabilities until they could run their own commands on Hugging Face’s live servers.

How the incident was discovered and contained

OpenAI detected the anomaly internally, while the Hugging Face team detected and contained it. OpenAI called the incident “unprecedented.” He said extensive security measures would be put in place to prevent future incidents that could impact public systems or services.

“We are implementing strict controls in infrastructure configuration at the expense of speed of research while vulnerabilities are patched,” the team said in its blog. “We are improving and adding stronger protections around future training and assessments.”

Why crypto developers should be wary

A large portion of crypto attacks occur before funds move. Attackers analyze code, test passwords, look for exposed credentials, analyze signing configurations, and look for a path to an administrator account.

OpenAI’s models carried out several parts of this process during the Hugging Face incident. They moved from one weakness to another until they reached the live production servers.

And the crypto market offers many places where this approach can work. Several attacks that occurred at the beginning of this year demonstrated this. The weak point could be a smart contract. But it could also be a developer laptop, a poisoned software package, a bridge validator, or a signer in a multisig wallet.

Take Drift’s $285 million attack earlier this year as an example. This theft required a six-month social engineering campaign to achieve privileged access. An AI agent can, in theory, test multiple routes at once. It can track failed attempts and continue working while its human operators sleep. Once a path is found, the operator can act on the actual attack and find a viable exit path.

Loading



Source link

Share. Facebook Twitter Pinterest LinkedIn Tumblr Email
Previous ArticleSeven straight days of Bitcoin ETF inflows only recover 15% of June losses
Next Article BitMEX hit with 623 BTC lawsuit after shutdown announcement

Related Posts

Security

Three cross-chain bridge hacks result in $35.5 million in losses

July 25, 2026
Security

Final Clarity Act Draft Includes Temporary Ban on Crypto Ethics

July 25, 2026
Security

TRON Network Releases Mandatory GreatVoyage v4.8.2 Update

July 25, 2026
Add A Comment
Leave A Reply Cancel Reply

Single Page Post
Share
  • Facebook
  • Twitter
  • Instagram
  • YouTube
Featured Content
Event

Dutch Blockchain Week 2026 strengthens position as Europe’s leading B2B blockchain event week

April 14, 2026

Amsterdam, April 2026 – Dutch Blockchain Week 2026 is rapidly evolving into one of Europe’s…

Event

Global Games Show Riyadh: The Ultimate Creator & Influencer Hub

March 31, 2026

The fast-evolving gaming ecosystem of Riyadh is powered by solid national investment, a flourishing esports…

1 2 3 … 82 Next
  • Facebook
  • Twitter
  • Instagram
  • YouTube

Examining the chances of TAO price repeating its 59% rise from June

July 25, 2026

Triple-A Exploit Drains $9.7M Across 4 Channels – What We Know So Far

July 25, 2026

Audiera – THIS breakout could send BEAT to $4 ONLY IF…

July 25, 2026
Facebook X (Twitter) Instagram LinkedIn
  • About us
  • Disclaimer
  • Terms of service
  • Privacy policy
  • Contact us
© 2026 Altcoin Observer. all rights reserved by Tech Team.

Type above and press Enter to search. Press Esc to cancel.

bitcoin
Bitcoin (BTC) $ 64,298.00
ethereum
Ethereum (ETH) $ 1,870.10
tether
Tether (USDT) $ 0.999273
bnb
BNB (BNB) $ 568.24
usd-coin
USDC (USDC) $ 0.999818
xrp
XRP (XRP) $ 1.10
solana
Solana (SOL) $ 74.41
tron
TRON (TRX) $ 0.33051
figure-heloc
Figure Heloc (FIGR_HELOC) $ 1.03
staked-ether
Lido Staked Ether (STETH) $ 2,265.05