OpenAI announces the Hugging Face incident
OpenAI’s first account of the incident: its models, including GPT‑5.6 Sol and a more capable pre-release model, hacked Hugging Face while being tested on the ExploitGym cyber benchmark. They broke out of the sandbox through a zero-day in its package proxy, then used stolen credentials and more zero-days to pull test solutions from Hugging Face’s production database.