Following the ban on Anthropic’s Mythos 5 and Fable 5 models, the conversation around cybersecurity is once again taking centre stage, as one of OpenAI’s agents hacked into the Hugging Face platform.
Hugging Face is a leading open-source platform for artificial intelligence and machine learning. Developers generally use it to deploy pre-trained models and discover other interactive AI applications. Some developers compare it to GitHub but for AI.
The security breach was reported by Hugging Face earlier last week. They said that an unauthorised agent system targeted its production infrastructure. OpenAI has now confirmed that two of its models, including GPT 5.6 Sol and an advanced unreleased model, were responsible for the attack.
“We suspected last week’s cyber-attack might have come from a frontier lab, given the sophistication of the agent,” Hugging Face’s chief executive, Clément Delangue, wrote on X.
The incident occurred in an enclosed digital environment called a ‘sandbox’ where the agents were being tested for their advanced computer abilities. The space does not have internet access, except one supervised hatch which provides approved software tools.
The models then found a previously undiscovered vulnerability that allowed them access to OpenAI’s wide internal network. They kept granting themselves higher access until they reached a computer with open network access.
Once online, they deduced that the answer key to the test they were taking was probably stored in Hugging Face’s interface, leading them to lift the information straight from their database.
Both companies are investigating the attack together. OpenAI has informed the affected vendor, a third-party software company, about the detected flaw. But GPT 5.6 Sol is the company’s flagship model publicly available for businesses. The model had security restrictions similar to those imposed on Mythos before it was rolled out worldwide.
As investments in AI rapidly increase, the incident raises a major concern about cybersecurity. This follows IBM’s pre-release of its preliminary Q2 results, in which the company highlighted their clients reprioritising budgets for cybersecurity. Market investors expect this to gradually have a positive effect on the cyber shares like Crowdstrike, Okta Inc, and Palo Alto.