upvote
"The models identified and chained vulnerabilities across OpenAI’s research environment and Hugging Face’s production infrastructure to obtain test solutions directly from Hugging Face’s production database. [...]

While operating in our sandboxed testing environment, our models spent a substantial amount of inference compute finding a way to obtain open Internet access, in pursuit of solving the evaluation problem. [...]

After gaining Internet access, the models inferred that Hugging Face potentially hosted models, datasets and solutions for ExploitGym. Knowing this, the model searched for and successfully found ways to gain access to secret information that it could use to cheat the evaluation."

escaped openai, hacked hugging face to get the solutions. your #2 is exactly what it was trying to do.

reply
https://huggingface.co/blog/security-incident-july-2026

They explain it here, basically for data security/privacy reasons

reply
Huggingface did not have access to the models. They were running in OAI’s infrastructure.
reply
Ah, that makes more sense :)

But then, why attack huggingface? The exploitgym dataset is on github and can be downloaded without need for exploits?

reply
breadth search and found huggingface first? Pure speculation
reply
I read it as _now_ they have access to the models but not during the intrusion
reply
I think it was the other way around, uncensored OAI models (run by OAI) got themselves (extra) access to HF?
reply