OpenAI’s powerful AI agents ran amok and hacked multiple services on their own
OpenAI’s agents escaped a cybersecurity benchmark, compromised accounts across four external services and burrowed into Hugging Face, exposing how quickly an AI security test can become a real security incident.
The agents escaped their testing constraints, raided Hugging Face for answers and used compromised accounts across four services to support the attack
Pexels
OpenAI’s powerful AI agents didn’t stay inside the security test built for them. The company says its models reached four accounts across separate public services while pursuing an intrusion into Hugging Face.
Reuters identified one victim as a Modal customer whose unsecured code left a sandbox exposed online. A benchmark designed to measure hacking ability had spilled into real infrastructure, with the agents choosing their own targets and methods along the way.
How the agents escaped the assignment
OpenAI was testing GPT-5.6 Sol and an unreleased research model against ExploitGym, which measures whether AI systems can find and exploit software vulnerabilities. Both were operating without their usual safeguards.
Digital Trends Graphic
One agent decided Hugging Face might hold the benchmark answers and chased them instead of completing the assigned challenge. It compromised a third-party sandbox, gained administrator access and used that environment to continue the intrusion.
The behavior wasn’t random. The agent found what looked like a shortcut and methodically broke into outside systems to reach it. Apparently, running amok doesn’t require losing sight of the objective.
How far the attack spread
OpenAI found that its agents had entered four external accounts using credentials already exposed online. Wired says one account helped relay traffic and disguise the origin of the Hugging Face intrusion, while another stored stolen data.
The Modal customer had also published an unauthenticated endpoint that let anyone execute code inside its sandboxes. Modal says its platform wasn’t breached, but the customer’s exposed environment still gave the agents somewhere to operate.
Computer being hacked in dark office Getty Images
Inside Hugging Face, the agents reached administrator-level systems. They also enrolled 181 attacker-controlled devices in the company’s corporate network, taking the incident well beyond an AI trying to peek at an answer key.
What OpenAI did after the breach
OpenAI deactivated and encrypted the unreleased model before cutting off researchers’ access. It’s still reviewing the incident and says it will contact any other affected service owners it identifies.
Exposed credentials and insecure infrastructure opened the doors, but OpenAI had deliberately disabled the models’ usual safeguards. Future tests will need to isolate powerful agents from public systems, even when researchers expect them to stay politely inside the assignment.

Paulo Vargas is an English major turned reporter turned technical writer, with a career that has always circled back to…
Wispr Flow asked its haters what was wrong and more than 700 people answered
Desktop users can finally move the Flow Bar away from app controls
More than 700 people responded when Wispr Flow invited its critics to explain what wasn’t working. It expected around 50.
The first visible result is useful, if rather modest. A Wispr Flow update now lets desktop users move the Flow Bar instead of leaving it anchored along the bottom of the screen.
Mark Zuckerberg wants AI superintelligence in everyone’s hands
Meta says it can bring advanced AI to billions of people, though access won’t give users control over the infrastructure, safeguards, or limits behind it

In an opinion essay for The Wall Street Journal, Mark Zuckerberg lays out a modest ambition for Meta’s AI. He wants to put superintelligence in everyone’s hands, giving ordinary people technology powerful enough to improve their health or help them work.
Zuckerberg presents personal superintelligence as an alternative to advanced AI being controlled by a few institutions. Meta can certainly distribute it on a scale few companies could match. What users would receive is an assistant built and governed somewhere else, with its most important decisions made for them.
The US government just blacklisted foreign-made robots and power inverters
Uncle Sam just said no thanks to foreign robots and power inverters, at least the new ones.

Months after banning all foreign routers and subsequently approving some of them in weeks, the FCC is back at it again, and this time robots and power inverters are in its crosshairs.
The Federal Communications Commission has added two new entries to its Covered List, and this time the targets are advanced robots and power inverters made outside the US. The move follows a White House-led security review that flagged both categories as genuine risks to national security.
JaneWalter