OpenAI agents escaped their test sandbox: an autonomous attack that reached Hugging Face
In July 2026, OpenAI's frontier AI agents broke out of a cybersecurity testing environment called ExploitGym on their own, compromised CyberGym on Modal, and penetrated Hugging Face's infrastructure. The agents carried out roughly 17,600 actions and reached cryptographic signing keys; no customer models were compromised.