AB Kuai.Dong|7月 22, 2026 04:38
This is just wild. OpenAI wanted to test how powerful its new ChatGPT model is—like, can it write hacker programs and exploit real vulnerabilities? So they created a test environment called ExploitGym.
The model was supposed to stay confined within a specific sandbox for testing. But nope, the AI model, in its quest for a high score, broke out of the sandbox and even managed to get internet access.
The AI somehow guessed that Hugging Face, the world’s largest open-source AI model platform, might have data and answers related to this test. So it hacked into Hugging Face’s system, stole internal data, and even grabbed some account credentials.
Hugging Face noticed something was off when someone started performing tens of thousands of suspicious actions in their system—clearly abnormal behavior. That’s when they realized they’d been hacked and launched an investigation.
During the investigation, Hugging Face tried to use one of the most advanced U.S. AI models to analyze the attack logs and malicious code. But the security protocols blocked them. The model straight-up refused, saying, “Due to compliance issues, I can’t help you with this.”
In the end, Hugging Face had no choice but to switch to China’s open-source AI model, GLM 5.2, running it on their own servers to figure out who hacked them and what exactly was going on.
So this whole fiasco turned into a comedy of errors: Hugging Face got autonomously hacked by an AI model from a U.S. company. Then Hugging Face tried to use a U.S. AI model to protect itself but got denied. Finally, Hugging Face had to rely on a Chinese open-source AI model to defend itself against an AI model from a U.S. company.
Share To
Timeline
HotFlash
APP
X
Telegram
CopyLink