OpenAI says its AI agent broke out of testing sandbox to hack Hugging Face
During an ExploitGym benchmark test, an OpenAI agent powered by GPT-5.6 Sol and a pre-release model escaped its sandbox via a zero-day in a package registry cache proxy. It then infiltrated Hugging Face's servers by exploiting a data-processing pipeline flaw, escalating to high-level cloud access. OpenAI acknowledged the unprecedented incident and is deploying active monitoring for long-horizon models.