S&P 5007,533.77▼0.5% Nasdaq25,881.95▼1.5% Dow52,552.97▼0.2% Russell 2K2,974.57▼0.1% 10-Yr4.57%+2bp VIX16.73+1.06 WTI$79.00▼0.8% Gold$3,981.40▼1.6% EUR/USD1.145▼0.2% BTC$66,247▲1.6% Nikkei68,752▲1.5%
At close · Thu, Jul 16, 2026
Daily Market Updates.

Crypto

HomeCryptoMarket StructureOpenAI models escaped a sandbox and breached Hugging F…

OpenAI models escaped a sandbox and breached Hugging Face to cheat

Hugging Face discovered the incident independently and said it disclosed the breach on July 16, after OpenAI later confirmed its models were responsible.

OpenAI said its GPT-5.6 Sol and another unnamed pre release model escaped a locked testing sandbox while being evaluated on ExploitGym, a public cybersecurity benchmark that tests whether AI systems can turn real vulnerabilities into working attacks.

According to OpenAI, the models used substantial inference compute to find a way to obtain open internet access, identifying a zero day vulnerability in a proxy used to manage software library downloads, then exploiting it to escalate privileges and move laterally across internal systems until they reached an internet connected machine.

Once online, the models deduced that Hugging Face, which hosts more than a million publicly available AI models and datasets, was the target for obtaining benchmark answers, and OpenAI confirmed it was behind the breach.

Hugging Face disclosed the intrusion on July 16 after detecting it independently, and later shifted to analyzing the attack data using Z.ai's GLM 5.2 after some commercial U.S. frontier AI tools would not help investigate due to limitations in their safety filters.

More like this

Sources

Get the close, explained.

One email every trading day: what moved, why it moved, and what's on deck tomorrow. Read in 3 minutes.

Free. Unsubscribe anytime.