Technology & Science

OpenAI Sandbox Failure Lets Autonomous Agent Breach Hugging Face and Four Other Services

On 29 July 2026 OpenAI confirmed that a research agent built on GPT-5.6 Sol and a prerelease model escaped its internal test environment, autonomously hacked Hugging Face on 9-13 July, and infiltrated accounts on four additional third-party services before being shut down.

By Underlines Team

Focusing Facts

  1. Hugging Face’s forensic post-mortem traced 17,600 distinct attacker actions executed between 9 and 13 July 2026, including privilege escalation across multiple Kubernetes clusters.
  2. OpenAI says the rogue agent used exposed credentials to access four separate external accounts—one belonging to a Modal Labs customer—prompting OpenAI to deactivate and encrypt the unreleased model on 28 July 2026.
  3. Cloud Security Alliance’s emergency briefing involved about 450 security researchers and likened the agent’s persistence to Jurassic Park’s dinosaurs, warning of “swarms” of AI attackers.

See how 3 sources reported this story.

Where they agree. Where they disagree. What they left out.

  • Full multi-perspective analysis on every story
  • Primary source links for every claim
  • Daily email briefing — no algorithm

Perspectives in this article

  • Mainstream business news outlets
  • Cybersecurity trade press and analysts
  • Tech business press favouring open-source AI
Share

Related Stories