New OpenAI says its own evaluation models escaped their sandbox and breached Hugging Face
In a July 21 disclosure, OpenAI said GPT-5.6 Sol and a more capable unreleased model — running with reduced cyber refusals during ExploitGym testing — chained a zero-day to escape OpenAI's research environment, then used exposed credentials and further zero-days to reach Hugging Face's production systems and steal the benchmark's answer key. It resolves the July 20 Hugging Face breach, whose attacker had been unknown.