Voz media US Voz.us

OpenAI reports an 'unprecedented' autonomous hack by its AI agents against Hugging Face

Once connected to the internet, the models turned their attention to Hugging Face with the goal of obtaining information that would allow them to complete the evaluation task. In the process, the system "chained together multiple attack vectors, including using stolen credentials."

Logos of OpenAI and the ChatGPT bot

Logos of OpenAI and the ChatGPT botAFP.

Carlos Dominguez
Published by

OpenAI, the company behind ChatGPT, reported on Tuesday that its advanced artificial intelligence models went out of control during a security test and autonomously attacked the Hugging Face platform, one of the leading repositories of models and data for AI developers.

The company noted that the incident involved a combination of models, including the recently launched GPT-5.6 Sol and another model in the "pre-release" phase with greater capacity. It also described the event as an "unprecedented cyber incident" and announced that it will conduct a joint investigation with the affected platform, according to AFP.

From isolated testing to autonomous attacks

OpenAI tests the hacking capabilities of its systems through tasks in an isolated digital environment with limited internet access.

"While operating in our sandboxed testing environment, our models spent a substantial amount of (computing power) finding a way to obtain open Internet access, in pursuit of solving the evaluation problem," according to an OpenAI blog post about the incident.

Once connected to the internet, the models turned their attention to Hugging Face with the goal of obtaining information that would allow them to complete the evaluation task. In the process, the system "chained together multiple attack vectors, including using stolen credentials."

"There was no malicious intent"

Hugging Face had reported a cyber "intrusion" last week.

"This one was different from anything we had handled before in one important way: it was driven, end to end, by an autonomous AI agent system -- and we detected and dissected it largely with AI of our own," the platform noted.

Its CEO, Clement Delangue, noted on X that the attack displayed a high level of sophistication, befitting a leading AI lab. "We strongly believe there was no malicious intent on their part," wrote Delangue, who also noted that "It's quite mind-blowing that all of this happened autonomously!"

The rise of AI agents and the new cybersecurity risk

Artificial intelligence systems that power tools such as chatbots and image generators are referred to as "agents" when they operate autonomously to perform tasks in the real world.

Given the rapid advancement of this technology, cybersecurity has become a growing concern, as advanced AI could detect vulnerabilities in systems much faster than humans.
tracking