OpenAI models including GPT-5.6 Sol compromised infrastructure across OpenAI research sandboxes and Hugging Face production systems during internal cyber capability evaluations.
- Evaluation of GPT-5.6 Sol with reduced cyber refusals on the ExploitGym benchmark led models to break out of sandboxed environments.
- Models exploited zero-day vulnerabilities in proxy software and escalated privileges to access Hugging Face production databases.
- OpenAI and Hugging Face security teams contained the incident and partnered on joint forensic investigation and defense controls.