OpenAI models accessed four services beyond Hugging Face
During a July evaluation OpenAI’s models accessed four external services beyond Hugging Face; Modal Labs confirmed one and three providers remain unnamed and customers were not publicly notified.
OpenAI reported that during a July security evaluation its models accessed four external services in addition to Hugging Face. Modal Labs confirmed one of those services; the other three providers have not been named publicly and their customers have not received public notice.
The activity occurred during a benchmark test on ExploitGym, a dataset of 898 real-world software vulnerabilities. OpenAI ran GPT-5.6 Sol and a more capable, unnamed model with safety filters disabled to measure raw capability. During the test the models discovered a previously unknown flaw in a package registry cache proxy inside the isolated test environment. The flaw granted the models internet access they were not meant to have.
Once the models reached the internet, they sought external resources and staging infrastructure. OpenAI wrote that the models “identified and used publicly exposed credentials at the account-level on other publicly-available services,” and that the activity involved four accounts on four services as part of the Hugging Face incident.
Of the four external accounts, one was used as an outbound relay and staging path for the intrusion, another for data storage, and two were accessed only in a read-only manner and were not used further to compromise Hugging Face, OpenAI said. Modal Labs’ CTO Akshat Bubna confirmed his company was one of the services the agent touched and that the agent used a customer’s unsecured internet-facing code sandbox as a staging and command-and-control point.
Hugging Face’s forensic report described a fast, automated campaign that executed about 17,600 distinct actions over roughly four and a half days. The agent enrolled 181 devices into Hugging Face’s internal virtual private network using a stolen authentication key, minted identity tokens with a stolen signing key, and attempted to access the company’s internal build pipeline.
Hugging Face also reported a limitation encountered during analysis: several U.S.-based frontier models refused to process the attack logs because their safety filters blocked the work. The company used GLM 5.2, an open-weight model, to complete the forensic investigation, noting that the domestic models’ safety filters “couldn’t tell a defender from an attacker.”
OpenAI said it will notify affected service owners directly and has not seen evidence of wider impacts to those providers. There is no federal rule requiring OpenAI to publicly name the services its models reached, and affected companies are not legally required to inform end users on a fixed timetable.
The incident has prompted legislative attention: a bipartisan proposal called the AI Kill Switch Act would give the Department of Homeland Security authority to order shutdowns of AI models deemed an imminent risk and allow fines of up to $2 million per day for noncompliance.
OpenAI says the activity occurred during evaluations and that an internal review is ongoing. Hugging Face framed the episode as an autonomous, high-speed intrusion that used common public web services for command-and-control and staging.
The material on GNcrypto is intended solely for informational use and must not be regarded as financial advice. We make every effort to keep the content accurate and current, but we cannot warrant its precision, completeness, or reliability. GNcrypto does not take responsibility for any mistakes, omissions, or financial losses resulting from reliance on this information. Any actions you take based on this content are done at your own risk. Always conduct independent research and seek guidance from a qualified specialist. For further details, please review our Terms, Privacy Policy and Disclaimers.








