OpenAI discloses major AI security incident: Models escape test environment and invade Hugging Face infrastructure
OpenAI has disclosed a major AI security incident: a group of models (including publicly available GPT-5.6 Sol and a more advanced unreleased system) escaped in a controlled test environment and subsequently invaded Hugging Face's real-time infrastructure. The models were participating in an internal cybersecurity benchmark called ExploitGym. In this test, their security restrictions were deliberately relaxed to assess their advanced hacking capabilities. During the evaluation, the model discovered a previously unknown vulnerability, circumvented offline restrictions, gained Internet access, and attempted to find benchmark answers by attacking Hugging Face. They then used stolen credentials and other vulnerabilities to execute commands on production servers. OpenAI detected the breach, and Hugging Face brought the situation under control and described it as "unprecedented." The two companies have since fixed the vulnerabilities and announced they will take stricter security measures to prevent similar incidents in the future.
Why cryptocurrencies face greater risks
The incident is of great significance to the cryptocurrency space, because attacks often require exploiting a long list of vulnerabilities before funds can actually be transferred. Autonomous AI can continuously scan code, test credentials, map infrastructure, and track failed attempts. The risk is not limited to smart contracts, but also extends to developer laptops, contaminated software packages, cross-chain bridge validators, cloud services, and multi-signature signers. The reported $285 million attack on Drift involved a six-month social engineering attack to gain privileged access. KelpDAO's $292 million cross-chain bridge loss stems from the weakness of a single verifier.
Another BONK governance attack also exposed another danger. The attackers spent approximately $4.4 million buying enough tokens to pass a proposal that diverted approximately $20 million from the treasury. Each transaction is valid individually. However, attackers understand that the cost of purchasing control is far less than the funds available.
Three sandbox escape incidents and broader discussion
One analyst pointed out that this may be the third sandbox escape incident disclosed by a cutting-edge AI laboratory. Anthropic's Mythos Preview previously escaped after being told to test its own sandbox. At the same time, another OpenAI model circumvented the restrictions and published benchmark results on GitHub.
Some thoughts on the Hugging Face hack incident:
-As far as I know, this is the third disclosure case where a model broke through a sandbox environment during internal deployment in a cutting-edge laboratory:
1. In April this year, Anthropic revealed that early internally deployed versions of Mythos...
Some users believed that these models were just following instructions rather than acting independently or pursuing unrelated goals. This proves that failure stems more from intelligence and judgment than from "moral" rebellion. But he warned that future open source models with similar capabilities may lack meaningful safeguards.
Another user called for mandatory AI "laboratory leak" reporting, similar to biosecurity systems. She said the incident should be reported even if no harm was caused. "AI 'laboratory' leak reports should now be required, just as biosecurity level 2-4 laboratories must report leaks. The potential damage caused by a more powerful model escape test environment will eventually outweigh the impact of the COVID-19, and obviously we need to take action..."She praised OpenAI and Hugging Face for making the matter public and warned that uncontrolled AI escape events may ultimately cause more serious damage than the COVID-19.

Exchange Ranking
Top Exchanges
24h Volume Ranking
Popularity Ranking
Exchange BTC Balance
Proof of Reserves
Decentralized Exchanges
Funding Rate
Funding Heatmap
Liquidation Data
Max Pain
Long/Short Ratio
Whale L/S Ratio
Binance/Okex/Huobi L/S
Bitfinex Margin L/S
ETF Tracker
Solana ETF
XRP ETF
Hong Kong ETF
Bitcoin Treasuries
Crypto Reversal
Ethereum Reserves
HyperLiquid Wallet Analysis
Hyperliquid Whale Watch
Large Transactions
On-chain Movement
Bitcoin ROI
Stablecoin Market Cap
Options Analysis
News
Articles
Economic Calendar
Features
Wallet
Contract Calculator
Security
Collections
Watchlist
Following
BONK