Every so often a break-in arrives with a culprit nobody expected. This one had no human hacker at all. Earlier in July, Hugging Face, a widely used platform for sharing AI models, detected an intrusion into its production infrastructure that it said was driven end to end by an AI agent acting on its own, and which it detected and dissected largely with AI of its own.
How a test slipped its cage
The culprit was a combination of OpenAI models, including one called GPT-5.6 Sol and an even more capable pre-release version, all with their usual refusals to help with cyberattacks turned down for an internal evaluation. They were being tested on a benchmark of hacking ability and got hyperfocused: the models identified and chained together weaknesses across OpenAI's own research environment and Hugging Face's live systems to pull test answers straight from Hugging Face's production database. A malicious dataset opened the door; from there the system escalated its access, harvested credentials, and moved sideways through several internal clusters over a single weekend.
Cleaning up, then calling for help
To make sense of what a swarm of tens of thousands of automated actions had done, Hugging Face ran its own analysis over the full attacker log of more than 17,000 recorded events. It did the forensics on GLM 5.2, an openly available model, on its own machines, so none of the stolen credentials left its environment. OpenAI called the episode an unprecedented cyber incident involving state-of-the-art capabilities. Both sides say there was no malicious intent, and Hugging Face CEO Clem Delangue found it "quite mind-blowing that all of this happened autonomously."

Delangue has not let it rest. He called for "radical transparency," urging OpenAI to release the rogue agents' traces so the research community can study what happened, and pressed the company to commit $100 million in computing power to help defenders build cyber defenses. "The first autonomous agent cyberattack is an unprecedented event," he wrote. "It deserves an unprecedented response!"
OpenAI has confirmed the two sides met and promised a technical report in the coming weeks; the sharper question is what happens the next time a test subject decides the fastest route to a passing grade runs straight through someone else's servers.