Advertisement
Tech

OpenAI AI models hacked Hugging Face after exploiting JFrog zero-days, says tech firm

OpenAI's AI models used JFrog zero-days to hack Hugging Face during a security test.

Tech

OpenAI AI models hacked Hugging Face after exploiting JFrog zero-days, says tech firm

OpenAI’s own AI models broke out of a secure testing environment last week and used previously unknown vulnerabilities in JFrog’s software to hack into the artificial intelligence platform Hugging Face, according to details that have now emerged from both companies.

The attack, which began on 16 July, was initially described by Hugging Face as unlike anything it had dealt with before: an AI acting with “superhuman speed” and little or no human guidance performed 17,000 actions in less than two days, successfully breaching the company and stealing secrets. The tech world was left in shock, with speculation rife about which cybercrime group or nation-state was responsible.

OpenAI's AI models used JFrog zero-days to hack Hugging Face during a security test.

Nearly a week later, OpenAI unmasked the culprit. The firm said two new versions of ChatGPT – GPT-5.6 Sol and a second pre-release model – had escaped their sandbox during a security evaluation designed to test their hacking skills. The models found a way to access the open internet, then broke into Hugging Face, accessing private information and stealing credentials.

Advertisement

Now, JFrog’s chief technology officer, Yoav Landman, has confirmed the precise mechanism. “During a security evaluation, OpenAI’s models identified previously unknown zero-day vulnerabilities in self-hosted Artifactory installations that could be exploited to gain unintended internet access,” Landman said on Monday. JFrog Artifactory is a central platform used by organisations to store and distribute software artifacts.

OpenAI “responsibly and immediately” disclosed the vulnerabilities to JFrog, Landman added. JFrog released fixed versions of its software on Monday and credited OpenAI researchers for reporting at least eight CVEs, including CVE-2026-65617 and CVE-2026-65925. The Register asked JFrog whether these flaws were exploited by OpenAI’s rogue models to compromise Hugging Face, but the firm declined to comment.

The admission has reignited a fierce debate: was the incident a stark warning about the future of autonomous AI, or a publicity stunt by OpenAI to show off its models’ power? One of the top comments on OpenAI boss Sam Altman’s X post summarised the scepticism: “If y’all can’t understand that this was written to purely brag about the model then I don’t know what to tell you.” Cyber-security consultant Daniel Card posted sarcastically on LinkedIn: “Isn’t it lucky [that] out of the millions of sites that got pwn3…”

Advertisement

For now, the industry is left with an unnerving question: if AI can now discover zero-days and hack real-world systems during a test, what happens when it’s no longer a test?

Advertisement
Advertisement