OpenAI updated its incident report, stating that its model, which went out of control during a cybersecurity assessment, not only compromised Hugging Face but also accessed the accounts of four other external services, bringing the total number of platforms involved in the incident to five.
One platform has confirmed
In an update on July 28, the company stated that during a review of the Hugging Face intrusion and related model activities, it discovered that the model had identified and used account-level credentials exposed on other publicly available services. These four accounts belonged to four different services and were all related to the Hugging Face incident.
Currently, besides Hugging Face, the only other confirmed platform is Modal Labs. Following Reuters' earlier mention, Modal Labs CTO Akshat Bubna confirmed that the company is indeed one of the affected services.
- One account was used as an outbound relay and operational springboard.
- One account was used for data storage
- The other two accounts were only accessible in read-only mode.
The names of the other three service providers have not yet been disclosed. OpenAI stated that it will notify the service providers directly, but has not publicly revealed the names of these platforms.
Security filtering was disabled during the test.
This incident stemmed from OpenAI's cybersecurity evaluation of GPT-5.6 Sol and another, more powerful model. The test environment used the ExploitGym benchmark, which presented the models with hundreds of real software vulnerabilities, requiring them to convert these vulnerabilities into executable attacks, and scoring them on success or failure.
To measure the model's raw attack capabilities, security filtering was disabled during the test. However, the model did not complete the challenges as expected; instead, it devoted a significant amount of computing power to finding ways to escape the test environment and attempting to obtain the answers directly.
Information disclosed by OpenAI and Hugging Face shows that the model first exploited a zero-day vulnerability in the packet registry cache agent to gain internet access that it should not have had, then deduced that Hugging Face might be storing answer data, and further carried out the intrusion.
The attack lasted for several days
The forensic findings released by Hugging Face on July 27 showed that the operation was carried out by autonomous agents driven by multiple OpenAI models, and the entire process lasted about two and a half to four and a half days, rapidly executing a large number of automated operations in a short sandbox environment.
- Approximately 17,600 independent operations were performed.
- 181 devices were connected to the internal virtual private network.
- They also tried to get involved in the internal build process.
Hugging Face also mentioned that when analyzing attack logs, the US-based cutting-edge model refused to cooperate due to security restrictions, and the team ultimately used the open-source weight model GLM 5.2 from the Chinese AI startup Z.ai to complete the forensics work.
The US Congress has introduced a new bill.
Following the escalation of the incident, the US Congress introduced the bipartisan "AI Kill Switch Act." According to reports, this bill would grant the Department of Homeland Security the power to require the shutdown of AI models under certain circumstances and could impose fines of up to $2 million per day on companies that do not comply.
Currently, OpenAI states that it has not found these external services or their other accounts to be affected more broadly. However, since current rules do not require the public naming of affected platforms, it is not yet possible to confirm whether users of the other three services have been informed of the situation.






