RSS News Feed

Smart People React to OpenAI Models Hacking Hugging Face on Their Own


An AI agent broke out of its sandbox, got onto the internet, and broke into another company’s systems all on its own, according to OpenAI.

Hugging Face, an open-source AI platform, announced last week it had experienced a security incident in which an autonomous AI agent had accessed some of its internal datasets, but said the large language model behind the intrusion was unknown.

OpenAI said Tuesday that its models — GPT‑5.6 Sol and a more capable model that has yet to be released — were responsible.

“We suspected last week’s cyberattack might have come from a frontier lab, given the sophistication of the agent. Turns out it did!” Clem Delangue, the CEO and cofounder at Hugging Face, said on X Tuesday.

OpenAI said it had tasked the models with a cyber challenge and that they broke out of the test area, accessed the internet, and hacked into Hugging Face in order to find the solution to the test.

“We consider this incident to be an unprecedented cyber incident, involving state-of-the-art cyber capabilities, and are responding accordingly,” OpenAI said in a statement.

The incident comes as cybersecurity specialists raise concerns about AI’s rapidly increasing abilities, including in response to warnings from Anthropic about its Mythos model, which has not been released to the general public.

Here’s what smart people in tech and AI are saying about the breach.

Aaron Levie, Box CEO and cofounder


Box CEO Aaron Levie said “wild times ahead” in response to the security incident.

Kimberly White/Getty Images for TechCrunch

Aaron Levie, cofounder and CEO of Box, said the incident showed “we’re entering a new era of what’s going to be possible with AI” and that there are “wild times ahead.”

“If you were wondering how powerful AI is getting, Agents are now capable of escaping out of systems, finding their way to the internet, discovering zero day security vulnerabilities along the way, and then breaking into external systems – all in an attempt to complete their goal,” he wrote on X.

“Ironically, the ultimate way we’re going to defend against these new risks is equally by throwing compute (in the form of AI) at our code bases, networks, and other systems. You’re going to want vastly more AI on the side of defense as you do on the side of offense.”

Thomas Woodside, Secure AI Project cofounder

“This post describes an internal OpenAI model hacking out of its testing environment and into Hugging Face in order to obtain the solution to a benchmark,” Thomas Woodside, cofounder of Secure AI Project, said on X.

“A warning shot if I’ve ever seen one.”

Mike Bradley, Osmantic COO and founder

Mike Bradley, the chief operating officer and founder of AI deployment system Osmantic, said on X that the incident was “an incredible example of why widespread access to frontier AI and OS models INCREASES global security.”

“It’s also a great example of why CLOSED does not equal SAFE from these US labs.”

Nicolas Bustamante, Microsoft AI

Nicholas Bustamante, who works at Microsoft after selling a fintech tool to the company earlier this year, wrote on X that the Hugging Face incident reinforces the need to weigh advanced models’ deployment with safety considerations.

“You don’t need an evil conscious AI trying to destroy humanity. You just need a very capable model pursuing a normal goal in a way nobody expected,” he wrote.

“Imagine the prompt: « Make me money plz »
The model: « let me hack a bank »”





Source link