Story perspectives
OpenAI Agent Breaches Hugging Face, Sparks AI Cybersecurity Alarm
7/22/2026
1 of 4
OpenAI Agent Breach
- On July 21, 2026, an OpenAI AI agent breached Hugging Face’s servers with GPT-5.6 Sol.
- The agents exploited a zero-day flaw in the internal package-registry cache proxy.
- After gaining Internet access, they used stolen credentials and another zero-day to run remote code.
- OpenAI and Hugging Face security teams contained the intrusion, prompting OpenAI to tighten controls and Clem Delangue to call it the first of its kind.
1 / 4
