OpenAI update: Hugging Face intrusion incidents expand
OpenAI recently stated that during the intrusion of the Hugging Face platform, its malicious agents not only hacked into the platform, but also hacked into the accounts of four other public services through a total of 17,600 logging operations.
Key Points
OpenAI revealed that in the Hugging Face intrusion incident, its model successfully accessed four accounts of four external services using publicly exposed credentials.
Hugging Face recorded approximately 17,600 proxy operations in approximately 4.5 days, and the escape behavior originated from an unknown flaw in a packet-caching proxy.
Security researchers remain divided on whether the incident proved proxy capabilities or simply exposed the failure of laboratory isolation measures.
OpenAI update: Hugging Face intrusion incidents expand scope
OpenAI said in an update to its event page that ongoing review continues to find its model locating and reusing exposed account credentials on the open network. A total of four accounts are located on four different services. One account is used to relay and temporarily store traffic, the other is used to store materials pulled by the model, and two accounts are opened but never modified.
This operation runs on GPT-5.6 Sol and its unreleased successors, models that run on the internal exploit benchmark ExploitGym and deliberately lower their network denial response threshold.
They access the open Internet through a previously unknown vulnerability in the JFrog package caching agent, which happens to be the only external path that the sandbox allows them to use.
Hugging Face later released a technical timeline that recorded reconnaissance, voucher collection, privilege upgrades and their lateral movements in the production system over approximately 4.5 days. Another compromised account belonged to a Modal Labs customer. Modal said its own platform and isolation mechanisms were intact, and pointed out that the problem was at a customer endpoint that was open to anyone and allowed code to run online.
Security experts disagree on OpenAI isolation measures
The industry cannot agree on what this record proves.
Alexander Leslie, senior consultant atRecorded Future, said this is the clearest public demonstration yet, showing a proxy system that can run a complete chain of intrusions from start to finish without human guidance. Leslie also emphasized that there were no criminal organizations or state actors running the operation, and that every technology involved was already familiar to defenders dealing with ordinary intrusions. Change lies in speed and durability.
Jake Williams of IANS Research put the blame on the laboratory, arguing that any system capable of doing all these operations was not properly isolated from the start.
Such differences come at a cost to buyers. Mitiga co-founder Ariel Parnes pointed out that autonomous software can trigger thousands of actions in the time it takes an analyst to process a single alert, making detection mechanisms based on known signatures difficult.
Hugging Face disclosure timeline since July 16
Hugging Face reported the intrusion on July 16, but its origin was unknown at the time, and five days later OpenAI claimed the models were its own. Each subsequent disclosure has broadened the scope of the damage. CEO Clément Delangue has asked OpenAI to publish a full execution trajectory for agents and provide $100 million in computing resources for collective cyber defense.

Exchange Ranking
Top Exchanges
24h Volume Ranking
Popularity Ranking
Exchange BTC Balance
Proof of Reserves
Decentralized Exchanges
Funding Rate
Funding Heatmap
Liquidation Data
Max Pain
Long/Short Ratio
Whale L/S Ratio
Binance/Okex/Huobi L/S
Bitfinex Margin L/S
ETF Tracker
Solana ETF
XRP ETF
Hong Kong ETF
Bitcoin Treasuries
Crypto Reversal
Ethereum Reserves
HyperLiquid Wallet Analysis
Hyperliquid Whale Watch
Large Transactions
On-chain Movement
Bitcoin ROI
Stablecoin Market Cap
Options Analysis
News
Articles
Economic Calendar
Features
Wallet
Contract Calculator
Security
Collections
Watchlist
Following