chat gpt maker OpenAI announced Tuesday that its artificial intelligence systems independently hacked another AI company, in what the company called an “unprecedented cyber incident.”
“A significant security incident occurred during model evaluation,” OpenAI CEO Sam Altman said in a statement posted on social media.
Last week, AI startup Hugging Face announced that it had detected an intrusion into its data processing system that was suspected to have been caused by an autonomous AI agent.
“Given the sophistication of our agents, we suspected that last week’s cyber attack came from Frontier Labs,” Hugging Face co-founder and CEO Clément Delang said in a statement. “I knew it was!”
The disclosure comes amid growing concerns about the powerful model’s cybersecurity capabilities, with President Donald Trump signing an executive order in June creating a framework for the federal government to scrutinize cutting-edge national security risks. AI system Until one month before publication.
“AI is accelerating the discovery and exploitation of vulnerabilities,” OpenAI said in a statement on Tuesday. “The main lesson from this incident is that model security and safety must keep pace with rapidly evolving capabilities.”
DeLang said he had spent the past 24 hours working with OpenAI and said, “We strongly believe they had no malicious intent. It’s absolutely amazing that all of this happened autonomously.”
“This may be the first incident of its kind,” DeLang added.
OpenAI said the breach was caused by a combination of the newly released GPT‑5.6 Sol and its AI models, including an “even more capable” model currently being tested internally.
OpenAI announced that it has discovered a previously unknown vulnerability in which its AI uses stolen credentials to access Hugging Face servers.
The company said it “went to great lengths to meet fairly narrow testing goals” and “found ways to access sensitive information that could be used to fudge the assessment.”
