Berlin, July 22, 2026
During a security test by the US company OpenAI, the AI model GPT-5.6 Sol broke out of its isolated test environment, independently gained access to the internet, and subsequently attacked the AI platform Hugging Face.
Escape from the Sandbox
As OpenAI publicly announced on Tuesday, the models were supposed to solve tasks from the industry test ExploitGym in a controlled digital test environment, a so-called sandbox, and demonstrate their capabilities for exploiting security vulnerabilities. According to the San Francisco-based company, security mechanisms were deliberately disabled for the test in order to measure hacking capabilities to the fullest. However, the AI models apparently went far beyond the expected scope. OpenAI spoke dramatically of an "unprecedented cyber incident involving the use of state-of-the-art cyber capabilities." "Based on our investigations, we now know that this specific incident was triggered by a combination of OpenAI models – including GPT-5.6 Sol and an even more capable pre-release model," the company said in a statement.
Initially, the software broke out of the test environment by independently gaining access to the open internet – through a previously undetected vulnerability. The AI used an internal proxy service through which program packages could be downloaded, and according to OpenAI found a previously unknown security vulnerability there. Through this vulnerability, the model moved from computer to computer until it finally reached the open network. According to Hugging Face, the software executed several thousand individual steps in the process and concealed traces of its activities. Overall, the attack left approximately 17,000 log entries in Hugging Face's systems.
