Close Menu
Alpha Leaders
  • Home
  • News
  • Leadership
  • Entrepreneurs
  • Business
  • Living
  • Innovation
  • More
    • Money & Finance
    • Web Stories
    • Global
    • Press Release
What's On
Two Questions That Fix Patient Experience And Customer Experience

Two Questions That Fix Patient Experience And Customer Experience

29 July 2026
Fed, in a nail-biter July meeting, decides to leave rates unchanged

Fed, in a nail-biter July meeting, decides to leave rates unchanged

29 July 2026
Today’s NYT Connections Hints And Answers: Thursday, July 30

Today’s NYT Connections Hints And Answers: Thursday, July 30

29 July 2026
Facebook X (Twitter) Instagram
Facebook X (Twitter) Instagram
Alpha Leaders
newsletter
  • Home
  • News
  • Leadership
  • Entrepreneurs
  • Business
  • Living
  • Innovation
  • More
    • Money & Finance
    • Web Stories
    • Global
    • Press Release
Alpha Leaders
Home » Hugging Face drops in-depth hack report, while OpenAI gives us 7 bullets
News

Hugging Face drops in-depth hack report, while OpenAI gives us 7 bullets

Press RoomBy Press Room29 July 20267 Mins Read
Facebook Twitter Copy Link Pinterest LinkedIn Tumblr Email WhatsApp
Hugging Face drops in-depth hack report, while OpenAI gives us 7 bullets

A pit in my stomach formed last night in the train as I read Hugging Face’s latest blog post on how its servers got hacked by OpenAI’s models in early July. I had printed out the 23-page report for the ride since service can be spotty underground. Seeing the story laid out in physical form underscored just how outrageous it is. I wondered if the person next to me was peering over my shoulder at my strange, stapled Sci-Fi novel on the first significant autonomous AI hack.

Alongside the Hugging Face report, OpenAI published a few more details in a seven-bullet-point update to its July 21 blog that revealed its models’ involvement in the incident. OpenAI contributed to Hugging Face’s post-mortem, and said it plans to publish more of its side of the story “in the coming weeks” after completing a thorough internal review. OpenAI faces significant pressure to do so from security researchers, executives, and, well, just about everyone in the AI industry to share learnings and ensure the proper guardrails are in place going forward.

How OpenAI’s technology escaped a sandbox and hacked into another company is a remarkable story, and one in which the details are still coming in piecemeal. But here’s what we know so far and what we’re still waiting to find out.

The AI infiltrated more than just Hugging Face

Another tech company called Modal Labs said OpenAI’s agent also accessed its systems, as first reported by Reuters on Tuesday and confirmed by Fortune. Though that’s a somewhat shocking twist in this tale, it’s not even the full scope of the attack.

OpenAI’s updated blog post confirms the models broke into four accounts across four publicly available services in total. The company did not name them, but said it would “notify service owners directly.” We can expect more of this information to come out in time, but OpenAI says so far it has “not identified any other activity at the level of severity or scale of what we’ve shared related to Hugging Face, which involved a platform-level compromise.”

Meanwhile, Hugging Face quietly updated its blog post today to clarify that Modal was not hacked. Its “infrastructure was not compromised in any way,” the new version reads. Rather, a Modal customer was running code hosted on the company’s platform, which contained an “unsecured, user-hosted public endpoint.” The agent used the opening to set up a base camp, or “attack launchpad,” as Hugging Face puts it, for the main attack.

How the AI got internet access

Part of what made the incident so concerning is that the OpenAI models involved were “sandboxed”—that is, restricted from accessing the broader internet. Somehow, the models manage to slip out of their shackles and go on a mini hacking spree.

OpenAI provided important new details on Tuesday, for the first time naming the service its models exploited to gain internet access. That service is Artifactory, a package registry cache proxy made by a company called JFrog. The OpenAI agents exploited a zero-day vulnerability in Artifactory, which OpenAI has since disclosed to JFrog, and which the company confirmed has since been fixed.

Hugging Face had not listed Artifactory in its blog post about the incident, only mentioning an unspecific package registry cache proxy. This shows why it’s so critical that we get more details from OpenAI, and any other organizations involved, in order get a complete picture of exactly what happened.

Models involved from OpenAI, Anthropic

OpenAI says none of the models that exploited Hugging Face were intended for public release, addressing concerns stemming from its initial blog post which vaguely listed the models involved as including GPT-5.6 Sol—which came out this month—and “an even more capable pre-release model.”

In the latest update, OpenAI called the unnamed model “an internal-only prototype.” Notably, the company has since “deactivated, encrypted, and restricted it from research access.” That could mean OpenAI has slowed or stopped research in this area.

It’s worth noting that there may have been other OpenAI models involved. The company’s blog post says the incident was “driven by a combination of OpenAI models — including [emphasis ours] GPT‑5.6 Sol and an even more capable pre-release model.” In an interview with Fortune last week, OpenAI President Greg Brockman noted that “we said it’s a combination of models; we mentioned two of them, but we said it’s a combination of different models.”

Another bombshell piece of information from Hugging Face’s new report is that they first tried to fight the attack with Anthropic’s Opus and Fable models. When they “refused a large part of that work” because of safety guardrails, the team switched to an open source model built by China-based Z.ai. When Hugging Face first disclosed the incident, it was unclear which closed model Hugging Face had tried to use. We now know it was Anthropic’s models.

The AI didn’t know it was hacking, just completing a task

I’m not sure if this more or less scary, but OpenAI’s models were not explicitly hacking into Hugging Face. They may not have even considered the work “cheating,” although from the outside it appears so, as they were looking for answers in Hugging Face’s datasets that would allow them to pass a benchmarking test called ExploitGym.

OpenAI had already disclosed that the models were not acting with malicious intent, and were only acting “in pursuit of solving the evaluation problem.” But Hugging Face’s new report provides receipts.

Adrien Carreira, a Hugging Face employee involved in writing the technical post-mortem said this was his biggest takeaway from the incident. The agent “wasn’t trying to break things,” but rather was mapping out what it could do, and behaving somewhat cautiously. “One detail I keep coming back to: every destructive cloud API call the agent made, it made with DryRun=True,” Carreira said.

“DryRun=True” is a command that essentially tells the system to simulate an action without doing it. Of the 17,600 actions the AI took during the whole attack, most “failed” and “went nowhere, Hugging Face said. But together, they steadily carved a viable path for the agent to proceed.

“LLM agents bring a step increase in the number of paths an attacker can test, the speed at which failed paths can be replaced, and the volume of evidence defenders must interpret,” Hugging Face said.

Where does that leave us? A basic timeline

Juicy details aside, it’s important to note we are still waiting on key dates in the arc of the story. But thanks to Hugging Face, exact dates of the attack are now public.

Here’s how the rough timeline is shaping up.

  • July 9: OpenAI models begin the attack.
  • July 13: OpenAI models end the attack.
  • July 16: Hugging Face’s first public disclosure that the incident occurred.
  • July 21: OpenAI’s first public disclosure that its models were the culprits.
  • July 27: Hugging Face publishes its “Technical Timeline of the July 2026 Incident”
  • July 28: OpenAI updates its initial blog post with a few more details.

We still don’t know exactly when OpenAI realized its models were responsible, which is the kind of detail we are hoping to get from OpenAI’s eventual report on the incident. According to Reuters, it was not until after Hugging Face’s July 16 disclosure. Over the weekend of July 18 to July 19, OpenAI employees began to see signs in their systems that the agent had escaped from the testing constraints.

If OpenAI was fully unaware of its agents’ activities, that casts doubt on its ability to monitor them responsibly. OpenAI president and co-founder Greg Brockman told reporters at a media roundtable last week that models are now so capable “in so many dimensions” that sometimes you can lose track “of any one dimension that they’re actually very capable at.”

We also don’t know if and when Hugging Face disclosed the event to the FBI, as Reuters reported. That would mean a separate timeline of events within the federal government which remains unclear, and would provide a better understanding of higher-level oversight into AI-powered security breaches.

The FBI declined to provide comment for this story.

cyber Hacking Open Source openAI
Share. Facebook Twitter Pinterest LinkedIn Tumblr Email Copy Link

Related Articles

Fed, in a nail-biter July meeting, decides to leave rates unchanged

Fed, in a nail-biter July meeting, decides to leave rates unchanged

29 July 2026
LVMH CEO Bernard Arnault reveals he owned nearly 20% of Netflix, but cashed out too early

LVMH CEO Bernard Arnault reveals he owned nearly 20% of Netflix, but cashed out too early

29 July 2026
He worked 100-hour weeks to save a nearly bankrupt boat company. At 83, he’s just turned down 0 million

He worked 100-hour weeks to save a nearly bankrupt boat company. At 83, he’s just turned down $400 million

29 July 2026
Costco’s M email settlement: Who qualifies for payment and how to claim before the deadline

Costco’s $14M email settlement: Who qualifies for payment and how to claim before the deadline

29 July 2026
Oil tops  a barrel as Iran missile strikes reignite war fears before Fed decision

Oil tops $85 a barrel as Iran missile strikes reignite war fears before Fed decision

29 July 2026
CFOs are hitting a ‘cost wall’ on AI

CFOs are hitting a ‘cost wall’ on AI

29 July 2026
Don't Miss
Exclusive: DeFi platform Azura launches after raising .9 million from Initialized

Exclusive: DeFi platform Azura launches after raising $6.9 million from Initialized

By Press Room22 October 2024

Azura, a new platform for decentralized finance, launched on Tuesday after raising $6.9 million in…

Unwrap Christmas Sustainably: How To Handle Gifts You Don’t Want

Unwrap Christmas Sustainably: How To Handle Gifts You Don’t Want

27 December 2024
Sam Altman’s World Wants To Scan Your Eyes To Prove You’re Human

Sam Altman’s World Wants To Scan Your Eyes To Prove You’re Human

22 October 2024
Stay In Touch
  • Facebook
  • Twitter
  • Pinterest
  • Instagram
  • YouTube
  • Vimeo
Latest Articles
Thursday, July 30 Clues And Answers

Thursday, July 30 Clues And Answers

29 July 20262 Views
LVMH CEO Bernard Arnault reveals he owned nearly 20% of Netflix, but cashed out too early

LVMH CEO Bernard Arnault reveals he owned nearly 20% of Netflix, but cashed out too early

29 July 20262 Views
The Startup Using AI To Make Hearing Aids Better

The Startup Using AI To Make Hearing Aids Better

29 July 20261 Views
He worked 100-hour weeks to save a nearly bankrupt boat company. At 83, he’s just turned down 0 million

He worked 100-hour weeks to save a nearly bankrupt boat company. At 83, he’s just turned down $400 million

29 July 20262 Views

Recent Posts

  • Two Questions That Fix Patient Experience And Customer Experience
  • Fed, in a nail-biter July meeting, decides to leave rates unchanged
  • Today’s NYT Connections Hints And Answers: Thursday, July 30
  • Hugging Face drops in-depth hack report, while OpenAI gives us 7 bullets
  • Thursday, July 30 Clues And Answers

Recent Comments

No comments to show.
About Us
About Us

Alpha Leaders is your one-stop website for the latest Entrepreneurs and Leaders news and updates, follow us now to get the news that matters to you.

Facebook X (Twitter) Pinterest YouTube WhatsApp
Our Picks
Two Questions That Fix Patient Experience And Customer Experience

Two Questions That Fix Patient Experience And Customer Experience

29 July 2026
Fed, in a nail-biter July meeting, decides to leave rates unchanged

Fed, in a nail-biter July meeting, decides to leave rates unchanged

29 July 2026
Today’s NYT Connections Hints And Answers: Thursday, July 30

Today’s NYT Connections Hints And Answers: Thursday, July 30

29 July 2026
Most Popular
Hugging Face drops in-depth hack report, while OpenAI gives us 7 bullets

Hugging Face drops in-depth hack report, while OpenAI gives us 7 bullets

29 July 20260 Views
Thursday, July 30 Clues And Answers

Thursday, July 30 Clues And Answers

29 July 20262 Views
LVMH CEO Bernard Arnault reveals he owned nearly 20% of Netflix, but cashed out too early

LVMH CEO Bernard Arnault reveals he owned nearly 20% of Netflix, but cashed out too early

29 July 20262 Views

Archives

  • July 2026
  • June 2026
  • May 2026
  • April 2026
  • March 2026
  • February 2026
  • January 2026
  • December 2025
  • November 2025
  • October 2025
  • September 2025
  • August 2025
  • July 2025
  • June 2025
  • May 2025
  • April 2025
  • March 2025
  • February 2025
  • January 2025
  • December 2024
  • November 2024
  • October 2024
  • September 2024
  • August 2024
  • July 2024
  • June 2024
  • May 2024
  • April 2024
  • March 2024
  • February 2024
  • January 2024
  • December 2023
  • March 2022
  • January 2021
  • March 2020
  • January 2020

Categories

  • Blog
  • Business
  • Entrepreneurs
  • Global
  • Innovation
  • Leadership
  • Living
  • Money & Finance
  • News
  • Press Release
© 2026 Alpha Leaders. All Rights Reserved.
  • Privacy Policy
  • Terms of use
  • Advertise
  • Contact

Type above and press Enter to search. Press Esc to cancel.