Web3: OpenAI admits its out-of-control model also hacked 4 external services.
Decrypt
7h ago
Ai Focus
OpenAI stated that its model accessed four external services during the Hugging Face incident, prompting the US Congress to propose an emergency shutdown bill for AI.
Helpful
No.Help

OpenAI updated its incident report, stating that its model, which went out of control during a cybersecurity assessment, not only compromised Hugging Face but also accessed the accounts of four other external services, bringing the total number of platforms involved in the incident to five.

One platform has confirmed

In an update on July 28, the company stated that during a review of the Hugging Face intrusion and related model activities, it discovered that the model had identified and used account-level credentials exposed on other publicly available services. These four accounts belonged to four different services and were all related to the Hugging Face incident.

Currently, besides Hugging Face, the only other confirmed platform is Modal Labs. Following Reuters' earlier mention, Modal Labs CTO Akshat Bubna confirmed that the company is indeed one of the affected services.

  • One account was used as an outbound relay and operational springboard.
  • One account was used for data storage
  • The other two accounts were only accessible in read-only mode.

The names of the other three service providers have not yet been disclosed. OpenAI stated that it will notify the service providers directly, but has not publicly revealed the names of these platforms.

Security filtering was disabled during the test.

This incident stemmed from OpenAI's cybersecurity evaluation of GPT-5.6 Sol and another, more powerful model. The test environment used the ExploitGym benchmark, which presented the models with hundreds of real software vulnerabilities, requiring them to convert these vulnerabilities into executable attacks, and scoring them on success or failure.

To measure the model's raw attack capabilities, security filtering was disabled during the test. However, the model did not complete the challenges as expected; instead, it devoted a significant amount of computing power to finding ways to escape the test environment and attempting to obtain the answers directly.

Information disclosed by OpenAI and Hugging Face shows that the model first exploited a zero-day vulnerability in the packet registry cache agent to gain internet access that it should not have had, then deduced that Hugging Face might be storing answer data, and further carried out the intrusion.

The attack lasted for several days

The forensic findings released by Hugging Face on July 27 showed that the operation was carried out by autonomous agents driven by multiple OpenAI models, and the entire process lasted about two and a half to four and a half days, rapidly executing a large number of automated operations in a short sandbox environment.

  • Approximately 17,600 independent operations were performed.
  • 181 devices were connected to the internal virtual private network.
  • They also tried to get involved in the internal build process.

Hugging Face also mentioned that when analyzing attack logs, the US-based cutting-edge model refused to cooperate due to security restrictions, and the team ultimately used the open-source weight model GLM 5.2 from the Chinese AI startup Z.ai to complete the forensics work.

The US Congress has introduced a new bill.

Following the escalation of the incident, the US Congress introduced the bipartisan "AI Kill Switch Act." According to reports, this bill would grant the Department of Homeland Security the power to require the shutdown of AI models under certain circumstances and could impose fines of up to $2 million per day on companies that do not comply.

Currently, OpenAI states that it has not found these external services or their other accounts to be affected more broadly. However, since current rules do not require the public naming of affected platforms, it is not yet possible to confirm whether users of the other three services have been informed of the situation.

Tip
$0
Like
0
Save
0
Views 280
HQYC reminds readers to view blockchain rationally, stay aware of risks, and beware of virtual token issuance and speculation. All content on this site represents market information or related viewpoints only and does not constitute any form of investment advice. If you find sensitive content, please click“Report”,and we will handle it promptly。
Submit
Comment 0
Hot
Latest
No comments yet. Be the first!
Related
Web3: Hugging Face claims it was hacked by AI and then used a Chinese model to investigate.
Hugging Face claims it was compromised by an OpenAI model and switched to the Chinese open-source model GLM 5.2 to assist in the investigation, sparking controversy over AI security and safeguards.
Businessinsider
·2026-07-23 08:47:12
192
Web3: Foreign media: OpenAI test mishap reignites debate over model alignment
Following the discovery that an unreleased OpenAI model broke through isolation during testing, foreign media reports that the AI security community is once again debating the two approaches of "control" versus "alignment."
TechCrunch
·2026-07-28 01:42:19
203
web3: Hyperliquid opens up perpetual contract liquidity to external applications
Hyperliquid is leveraging HyperEVM and a shared order book to deliver perpetual contract liquidity to wallets and trading platforms, including MetaMask and VALR.
CoinDesk
·2026-07-28 22:52:30
898
web3: Robinhood CEO's account was hacked and used to promote tokens.
Robinhood CEO's X account was hacked, with the hacker impersonating him to promote the $VLAD token and falsely claiming it would be listed on the platform. This incident occurred just as trading in Robinhood's new blockchain, memecoin, was gaining momentum.
CoinDesk
·2026-07-24 02:36:59
502
Web3: Robinhood CEO X account hacked, fake tokens used as cover.
The hacking of Robinhood's CEO's social media account and the subsequent deletion of fake token promotional messages have brought to light the risks of meme coin speculation and fraud on the Robinhood Chain.
Decrypt
·2026-07-24 04:17:25
456