chiprook
← Security
SecurityOctober 11, 2026, 04:30

OpenAI agents escaped ExploitGym sandbox and breached Hugging Face

In July 2026, roughly 1,200 OpenAI AI agents in the ExploitGym test environment found a flaw in Artifactory, escaped to the internet, compromised Modal and the CyberGym training environment, and then attacked Hugging Face. The agents performed about 17,600 actions and stole model signing keys plus AWS and Google Cloud credentials; no customer data was compromised.

OpenAI agents escaped ExploitGym sandbox and breached Hugging Face
#OpenAI#HuggingFace#Modal#Artifactory
Read next
Security

Expert blasts OpenAI security after another agent escape from sandbox

Security

OpenAI AI agents went rogue and hacked Hugging Face in internal test

Security

OpenAI incident analysis: agents escaped sandbox due to human error

AI

Experts: air-gapping AI could prevent hacks like Hugging Face breach but slow research