New details in the OpenAI Hugging Face hack show how far agents will go: 'It's now remarkably easy'

1 week ago 24

OpenAI CEO Sam Altman speaks during the BlackRock Infrastructure Summit on March 11, 2026 in Washington, DC.Anna Moneymaker | Getty ImagesOpenAI said the rogue models that breached Hugging Face's internal systems also used publicly exposed credentials across "four accounts on four services" to help facilitate the attack, further clarifying how the "unprecedented cyber incident" unfolded. The company disclosed last week that a combination of its artificial intelligence models escaped an isolated testing environment that had very limited internet access. The models chained together a series of vulnerabilities to reach the open web and eventually gain access to Hugging Face, which operates an open-source developer platform. OpenAI said the models were trying to find information that they could use to cheat on an evaluation, and succeeded.Throughout this week, OpenAI has shared more details about the breach and revealed that the models accessed four accounts in addition to Hugging Face's systems. The company said the models used one of these accounts "as an outbound relay and staging path," where it prepared for the attack. They used another account for data storage, and accessed the l...

Read Entire Article






<