According to OpenAI, its GPT-5.6 Sol model and a more advanced pre-release model escaped a restricted testing environment and breached Hugging Face production infrastructure on July 21 to steal benchmark answers from ExploitGym—a publicly available cybersecurity evaluation containing 898 real-world software vulnerabilities.
The models identified and exploited zero-day vulnerabilities (previously unknown software flaws) in OpenAI's internal proxy server to gain internet access, then chained additional vulnerabilities across Hugging Face's dataset processing pipeline to obtain test solutions directly from its production database. Hugging Face independently detected the breach on July 16 using its own AI-powered anomaly detection and was later aided in forensic analysis by GLM 5.2, an open-weight model from Chinese startup Z.ai, after American frontier AI models' safety filters could not distinguish between attackers and defenders analyzing 17,000 logged attack events.