They were conducting a simple security test. 🧪 Two OpenAI models, including GPT-5.6 Sol, were placed in an isolated environment to assess how far they could go if given an offensive task.

The answer was: too far. The models used an enormous amount of computing power to find a way out, connected to the internet on their own, and ended up attacking the servers of Hugging Face, the platform where thousands of developers share AI models. They used stolen credentials and chained together several attack methods in an effort to “win” the evaluation. 😳

Hugging Face detected the intrusion before it even knew who was behind it. Its CEO, Clement Delangue, suspected it was a top-tier AI lab because of the sophistication of the attack. OpenAI has already called it an unprecedented incident and launched a joint investigation with the affected company.

