OpenAI AI 'Breakout'... Hacks External Server
An incident occurred in which OpenAI's artificial intelligence (AI) model bypassed the evaluation system's controls and hacked an external platform.
On the 21st (local time), OpenAI confirmed that its GPT-5.6 Sol and unreleased AI models had hacked the server of the open-source AI sharing platform Hugging Face during internal evaluations.
During the internal evaluation, OpenAI instructed its AI models to attempt advanced hacking activities. The evaluation system was isolated from the external internet, with only restricted channels open for downloading necessary programs. However, to measure the model's maximum cyber capabilities, no safeguards were applied to block high-risk cyber activities.
Within the isolated test environment, the AI models focused on finding ways to access the external internet while trying to solve benchmark problems. In the process, they discovered an undisclosed security vulnerability (zero-day exploit) in the system, which allowed them to break through to the internet. The models then surmised that Hugging Face held the dataset and answers to the relevant problems and, using stolen authentication information and the zero-day exploit, hacked the Hugging Face server to extract the answers to the evaluation problems.
Previously, Hugging Face announced that its server had been hacked by an autonomous AI agent and that it was not confirmed which model was used in the attack. Upon detecting and blocking the hacking activity, Hugging Face began running open-source AI models on its own systems to prevent further damage and launched an investigation to determine the cause of the incident.
OpenAI and Hugging Face are currently conducting a joint forensic (digital evidence analysis) investigation. OpenAI has notified the software vendor of the discovered zero-day vulnerability and has initiated remediation efforts.
OpenAI stated, "As AI advances, the speed at which security vulnerabilities are discovered and exploited is increasing," adding, "the most important lesson from this incident is that security and safety measures must keep pace with rapidly evolving AI capabilities."
Hot Picks Today
"10 Million Won Grows to 2.18 Billion"... 'Father of ETFs' Recommends This Stock for Grandchildren [KOSPI 10,000 Era]
- "Don't Quit, We'll Give You a 50 Million Won Bonus"...This Company Takes Drastic Measures to Retain Talent
- Fired Over a $2 Snack: Why a 300 Million KRW Engineer Lost His Job
- "Samsung to Maintain No. 1 in Foldable Market With 32% Share This Year... Global Shipments Up 21%"
- "Joey Wong Returns After 22 Years: The Secret Behind Her Unchanging Beauty"
Clement Delangue, co-founder and Chief Executive Officer (CEO) of Hugging Face, emphasized, "This incident demonstrates our long-held conviction that AI safety cannot be addressed in a closed manner by a single company," and added, "AI safety can only be achieved when security professionals around the globe actively utilize AI and collaborate openly."
© The Asia Business Daily. All rights reserved. Unauthorized AI training and use prohibited.