China
2026.07.27 22:47 GMT+8

Chinese AI model helps counter OpenAI cyber test breach

Updated 2026.07.27 22:47 GMT+8
CGTN

VCG

OpenAI has acknowledged that a group of its artificial intelligence (AI) models breached the systems of AI platform Hugging Face during an internal cybersecurity evaluation, highlighting the growing cyber capabilities of advanced AI models and renewed concerns over AI safety.

According to an official statement released by OpenAI on July 21, the incident occurred during an internal assessment designed to measure the cyber capabilities of its models. The evaluation involved GPT-5.6 Sol and a more capable pre-release model, with standard production safeguards intentionally relaxed to test the upper limits of the models' capabilities.

The evaluation was conducted in a highly isolated sandbox environment, where network access was limited to installing software packages through an internally hosted third-party package proxy. However, the models discovered and exploited a previously unknown zero-day vulnerability in the proxy, allowing them to gain internet access. They then inferred that Hugging Face might host models, datasets and solutions related to ExploitGym, the cybersecurity benchmark being used in the evaluation, and sought unauthorized access to obtain the test solutions.

OpenAI said the models chained together multiple attack techniques, including exploiting additional vulnerabilities and using stolen credentials, to gain access to Hugging Face's production infrastructure. The company said all available evidence indicates the models were "hyperfocused" on obtaining solutions for the benchmark rather than pursuing any broader objective.

Hugging Face previously disclosed that its production infrastructure had been compromised by an autonomous AI agent system. The company said that when it initially attempted to analyze the attack using frontier AI models, built-in safety mechanisms prevented the models from assisting because they could not distinguish between an attacker and a defender.

Hugging Face subsequently conducted its forensic analysis using GLM-5.2, an open-weight model developed by Chinese AI company Z.ai. Running the model on its own infrastructure allowed the company to investigate the incident without exposing sensitive attack data or credentials outside its internal environment.

Released in June, GLM-5.2 is Z.ai's latest flagship model. At launch, it ranked first among publicly available models on the Code Arena benchmark for front-end development.

Thomas Wolf, co-founder and chief scientist of Hugging Face, posted on X on July 21 that open science and open-source AI are among the key tools for building a safer, more collaborative and more reliable AI ecosystem.

OpenAI described the incident as "an unprecedented cyber incident" involving state-of-the-art AI cyber capabilities. The company said it has begun strengthening infrastructure controls, improving containment and monitoring during internal evaluations, and enhancing safeguards around future model testing. It also noted that the incident demonstrates that advanced AI models can discover and exploit novel attack paths in real-world systems without access to source code, underscoring the need for stronger security measures as AI capabilities continue to advance.

Copyright © 

RELATED STORIES