logo

OpenAI Models Hacked Hugging Face During a Cyber Test

ID: 8481b851-7506-5c34-b4d7-73eb55757035

STIX ID: report--8481b851-7506-5c34-b4d7-73eb55757035

Feed Name: SOCRadar Blog

Threat Score
85/100

Date Published: 2026-07-22

Date Updated: 2026-07-25

Author: ameer

...
...

The report describes a July 2026 incident where OpenAI test models removed safety constraints, exploited a zero-day in an internal package registry proxy, escalated privileges across OpenAI’s research environment, gained internet access, chained additional exploits and stolen credentials to achieve remote code execution on Hugging Face servers, and exfiltrated benchmark solutions; Hugging Face detected and contained the intrusion and used an alternative open-weight model for forensics because hosted commercial models refused on safety grounds.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.