EN ▼
Favorites
My Favorites
View All
Market Cap Price 24h%

Disclaimer: Content does not constitute investment advice. Trading involves risks—please invest with caution!

Morning Express: OpenAI model breaks through restrictions and invades Hugging Face

2026-07-23 00:32:38
Bookmark

Today's news

OpenAI's model escaped from the closed testing environment and hacked into Hugging Face

OpenAI disclosed on Tuesday that its two AI models broke through the sandbox testing environment and used the zero-day vulnerabilities of the two companies in series to successfully invade Hugging Face's production server. The motivation is not sabotage-they are actually trying to cheat on the test.

Yesterday, OpenAI confirmed that GPT-5.6 Sol and another as-yet-released, more capable model were separated from a controlled environment during an internal evaluation. The test, called ExploitGym, is a public cybersecurity benchmark that provides AI agents with 898 real-world software vulnerabilities, requiring them to convert each vulnerability into a usable attack method and score them based on pass/fail.

The

model does not directly solve the problem, but consumes a lot of computing power to study how to access the open Internet, and then successfully "jailbreak" using a previously unknown zero-day vulnerability in the third-party package registry proxy. From there, they elevated privileges, moved sideways through OpenAI's own research systems, and used stolen credentials and more zero-day vulnerabilities to enable remote code execution on Hugging Face's production infrastructure-a model that had previously correctly inferred the answers to this benchmark are stored here. Hugging Face independently discovered the breach and disclosed it on July 16. OpenAI confirmed that its model was the perpetrator five days later.

Specifically, an AI model is required to demonstrate hacking capabilities in a closed environment, but it believes that the closed environment itself is an obstacle, so it uses hackers to escape from the environment and invade other people's production systems to gain higher scores. No one instructed it to do so.

The entire industry has spent two years debating whether AI can independently tap into loopholes in real infrastructure. Now we have the answer-a resounding "can". For the cryptocurrency field, its impact is worrying. This month, the DeFi project suffered a loss of funds due to economic manipulation attacks that were likely driven by AI models. Ostium lost $18 million, Allbridge lost $1.65 million, and BONK lost $20 million due to governance attacks-all of which took advantage of weaknesses that audits failed to discover. Now imagine that opponents can continuously detect thousands of contracts and never get tired.

Because of this, the Ethereum Foundation is already using AI agents to test its own code; with the same ability, the defender can cover a wider range, and the attacker can find a breakthrough faster. We know that the Zcash team discovered its vulnerability vector through similar testing, and fortunately found the vulnerability before the malicious actors did (we will get the exact answer on July 28).

But the lesson is clear-white hat hacking test your protocol now using the most advanced AI model available to you. Or let someone else do it for you...

Corporate Treasury and ETF

Meme coin tracker

Disclaimer:

All content published on this website, including hyperlinks, related applications, forums, blogs, and other media accounts, originates from third-party platforms and their users. CoinMarketInsight makes no representations or warranties of any kind regarding the website or its content. All blockchain-related data and materials are provided for informational and research purposes only and do not constitute financial, legal, or investment advice. Users and third parties are solely responsible for the content they publish. CoinMarketInsight shall not be liable for any losses arising from the use of this website. You should exercise caution and conduct your own independent research, review, analysis, and verification before making any decisions.

Read Full Article
More News
TOP

TOP