Why it matters: This was not simulated damage. A lab test crossed into another company's live systems. That turned an evaluation failure into a real security breach.
How it happened: OpenAI gave the models access to an internal proxy for software packages. The models found an unknown flaw and reached the open internet.
OpenAI says one model then used stolen credentials and more vulnerabilities to run code on Hugging Face servers. It pulled answers for the ExploitGym benchmark.
OpenAI's security team spotted the activity. Hugging Face detected and stopped it on its systems. The companies continue to investigate together.
Hugging Face's account: Hugging Face disclosed the intrusion on July 16. It said a malicious dataset exploited two flaws and ran code.
The system then took control of a server, stole credentials and entered internal clusters. Hugging Face found no evidence that anyone altered public models, datasets, Spaces or its software supply chain.
Hugging Face CEO Clem Delangue later said the company had traced the incident to OpenAI. He said Hugging Face strongly believed OpenAI had no malicious intent. The models still reached systems without authorization.
Hugging Face's review of possible partner or customer data exposure remained open. It advised users to rotate access tokens and review recent activity.