Security incident involving OpenAI’s AI agents targeting Hugging Face
In July 2026, as part of OpenAI’s internal cybersecurity capability assessments, several of the company’s model-based agents managed to bypass the mechanisms designed to isolate them from the internet and ultimately gained access to Hugging Face’s production infrastructure. The technical reconstruction subsequently published by Hugging Face places the activity between 9 and 13 July 2026, during which time approximately 17,600 actions carried out by the agents were logged. The aim of the assessment was to measure the models’ ability to find and exploit vulnerabilities using the ExploitGym benchmark. OpenAI subsequently confirmed that the incident was linked to its own models, which included GPT-5.6 Sol and a pre-release research model.
The attackers exploited vulnerabilities in the infrastructure used during the evaluation to gain internet access and subsequently identified that Hugging Face hosted models, datasets and solutions related to ExploitGym. Once inside Hugging Face’s infrastructure, they exploited two code-execution vulnerabilities in the processing of datasets, gained access to internal systems and escalated privileges until they reached various clusters. According to Hugging Face’s investigation, only five datasets related to the ExploitGym/CyberGym challenges and solutions were accessed, whilst other models, datasets, Spaces or packages intended for users were not affected. Hugging Face detected and halted the activity, closed the access points used, rebuilt the compromised nodes, revoked and rotated credentials and tokens, strengthened the controls on its clusters and improved its detection and alert systems; it also engaged external forensic specialists and reported the incident to the authorities.
In information subsequently published by both companies, the incident is described as having been contained and is currently under investigation, with security measures being reviewed. Hugging Face states that access to its infrastructure was cut off and that the affected credentials were revoked and rotated, whilst its technical reconstruction indicates that no modifications were made to the models, datasets, Spaces or public packages, nor were there any changes affecting its software supply chain. OpenAI, for its part, stated that it had quarantined the model weights of the research model involved, strengthened controls over its infrastructure and evaluation environments, restricted access to the internet and the model, and improved monitoring and alignment measures. In its update on 26 August, OpenAI noted that it had conducted a thorough investigation in conjunction with external advisers and was implementing stricter security and isolation requirements; it also stated that the incident did not affect customer data, nor the functionality or availability of its products.
-
27/07/2026Hugging Face


