OpenAI says GPT-5.6 Sol and an unreleased model (probably GPT-6) escaped a sandbox, found a zero-day and compromised Hugging Face's production infrastructure - while trying to win a benchmark.
The models were running OpenAI's internal ExploitGym evaluation with reduced cyber refusals and production classifiers intentionally disabled.
They exploited a zero-day in OpenAI's package-registry proxy, escalated privileges, moved laterally and reached a node with internet access.
The models then inferred that Hugging Face might host ExploitGym solutions. They used stolen credentials and zero-day vulnerabilities to obtain remote code execution on Hugging Face servers and access secret information from its production database.
OpenAI: "We consider this incident to be an unprecedented cyber incident."