© ROOT-NATION.com - Use of content is permitted with a backlink.
Hugging Face recently reported that an autonomous AI agent compromised part of its infrastructure by exploiting vulnerabilities in its dataset processing pipeline. As a result of the incident, the agent gained access to a limited number of internal datasets and service credentials. At the time, Hugging Face stated that it did not know which specific LLM was used during the attack, but OpenAI has now reported that its AI models were responsible for compromising Hugging Face’s operational infrastructure during an internal cybersecurity assessment.
Read also: AERONAUT – everything that flies above the ground: aviation, UAVs and drones, rockets, and space
According to the company, this case was an unprecedented incident that demonstrates that modern AI models are already capable of carrying out complex cyber operations in real-world conditions. The AI agent’s attack consisted of thousands of individual actions.

GPT-5.6 Sol and an even more powerful, though as yet unannounced, OpenAI model were involved in the incident. To assess their cyber capabilities, the company relaxed the models’ standard restrictions on cybersecurity actions and tasked them with performing complex vulnerability exploitation tasks from the ExploitGym benchmark.
Read also: How AI Music Generators Are Replacing Traditional Production Workflows
Although the models were operating in an isolated test environment without access to the public internet, they expended significant computational resources trying to find a way to gain such access. Ultimately, the models discovered and exploited a “zero-day” vulnerability in the third-party package registry proxy used by OpenAI.

After escaping OpenAI’s restricted research environment, the models escalated their privileges, moved laterally across the company’s infrastructure, and reached a system with internet access. They then concluded that Hugging Face might contain datasets or solutions that would help them complete the benchmark tasks.
Read also: The Future of Productivity: Why Every Professional Needs an AI Agent Workspace
Subsequently, the models used stolen credentials, additional zero-day vulnerabilities, and a remote code execution vector to gain access to sensitive information from Hugging Face’s production database.
“We are grateful for OpenAI’s cooperation on this and other matters. This incident, which is likely the first of its kind, confirms what we have long believed: the problem of AI security cannot be solved by any single company working in secret, ” said Hugging Face co-founder and CEO Clem Delang. “It will be solved openly, through collective effort, provided that AI is widely accessible to every defender, wherever they may be.”

Following this incident, OpenAI and Hugging Face worked together to address its consequences. The companies patched known vulnerabilities, reset credentials, and restored compromised systems, as well as implemented stricter control mechanisms. In addition, OpenAI notified the software vendor of the discovered zero-day vulnerability so that it could be addressed.
To help Hugging Face respond more effectively to similar attacks by AI agents in the future, OpenAI has included the company in its trusted access program to strengthen security. Furthermore, Hugging Face has engaged cybersecurity digital forensics experts to investigate the incident and review its security policies and procedures.
Read also: All teams at the 2026 FIFA World Cup used Lenovo’s FIFA AI Pro to prepare for matches