Trendingnow

1

He worked 100-hour weeks to save a nearly bankrupt boat company. At 83, he’s just turned down $400 million for it—and gave it all to charity instead

2

Costco's $14 million email settlement: Who qualifies for an up-to $500 payment and how to claim before the Aug. 24 deadline

3

Jamie Dimon says his stockbroker father taught him to invest with a 'brutally hard' childhood game

1

He worked 100-hour weeks to save a nearly bankrupt boat company. At 83, he’s just turned down $400 million for it—and gave it all to charity instead

2

Costco's $14 million email settlement: Who qualifies for an up-to $500 payment and how to claim before the Aug. 24 deadline

3

Jamie Dimon says his stockbroker father taught him to invest with a 'brutally hard' childhood game

Cybersecurity OpenAI

Hugging Face drops in-depth hack report, while OpenAI gives us 7 bullets. Here’s what we know now, and what remains a mystery

By Emily Forlini Emily Forlini

Senior AI Reporter Down Arrow Button Icon

By Emily Forlini Emily Forlini

Senior AI Reporter Down Arrow Button Icon

July 29, 2026, 1:27 PM ET

sam altman looks down while reporters ask questions

OpenAI CEO Sam AltmanBrendan SMIALOWSKI—AFP/Getty Images

Add Fortune on Google for similar content.

Add us on Google

Add us on Google

A pit in my stomach formed last night on the train as I read Hugging Face’s latest blog post on how its servers got hacked by OpenAI’s models in early July. I had printed out the 23-page report for the ride since service can be spotty underground. Seeing the story laid out in physical form underscored just how outrageous it is. I wondered if the person next to me was peering over my shoulder at my strange, stapled sci-fi novel on the first significant autonomous AI hack.

Recommended Video


Alongside the Hugging Face report, OpenAI published a few more details in a seven-bullet-point update to its July 21 blog that revealed its models’ involvement in the incident. OpenAI contributed to Hugging Face’s postmortem, and said it plans to publish more of its side of the story “in the coming weeks” after completing a thorough internal review. OpenAI faces significant pressure to do so from security researchers, executives, and, well, just about everyone in the AI industry to share learnings and ensure the proper guardrails are in place going forward.

How OpenAI’s technology escaped a sandbox and hacked into another company is a remarkable story, and one in which the details are still coming in piecemeal. But here’s what we know so far and what we’re still waiting to find out.

The AI infiltrated more than just Hugging Face

Another tech company called Modal Labs said OpenAI’s agent also accessed its systems, as first reported by Reuters on Tuesday and confirmed by Fortune. Though that’s a somewhat shocking twist in this tale, it’s not even the full scope of the attack.

OpenAI’s updated blog post confirms the models broke into four accounts across four publicly available services in total. The company did not name them, but said it would “notify service owners directly.” We can expect more of this information to come out in time, but OpenAI says so far it has “not identified any other activity at the level of severity or scale of what we’ve shared related to Hugging Face, which involved a platform-level compromise.”

Meanwhile, Hugging Face quietly updated its blog post today to clarify that Modal was not hacked. Its “infrastructure was not compromised in any way,” the new version reads. Rather, a Modal customer was running code hosted on the company’s platform, which contained an “unsecured, user-hosted public endpoint.” The agent used the opening to set up a base camp, or “attack launchpad,” as Hugging Face put it, for the main attack.

How the AI got internet access

Part of what made the incident so concerning is that the OpenAI models involved were “sandboxed”—that is, restricted from accessing the broader internet. Somehow, the models managed to slip out of their shackles and go on a mini hacking spree.

OpenAI provided important new details on Tuesday, for the first time naming the service its models exploited to gain internet access. That service is Artifactory, a package registry cache proxy made by a company called JFrog. The OpenAI agents exploited a zero-day vulnerability in Artifactory, which OpenAI has since disclosed to JFrog, and which the company confirmed has since been fixed.

Hugging Face had not listed Artifactory in its blog post about the incident, only mentioning an unspecified package registry cache proxy. This shows why it’s so critical that we get more details from OpenAI, and any other organizations involved, in order to get a complete picture of exactly what happened.

Models involved from OpenAI, Anthropic

OpenAI says none of the models that exploited Hugging Face were intended for public release, addressing concerns stemming from its initial blog post which vaguely listed the models involved as including GPT-5.6 Sol—which came out this month—and “an even more capable pre-release model.”

In the latest update, OpenAI called the unnamed model “an internal-only prototype.” Notably, the company has since “deactivated, encrypted, and restricted it from research access.” That could mean OpenAI has slowed or stopped research in this area.

It’s worth noting that there may have been other OpenAI models involved. The company’s blog post says the incident was “driven by a combination of OpenAI models— including [emphasis ours] GPT‑5.6 Sol and an even more capable pre-release model.” In an interview with Fortune last week, OpenAI president Greg Brockman noted: “We said it’s a combination of models; we mentioned two of them, but we said it’s a combination of different models.”

Another bombshell piece of information from Hugging Face’s new report is that it first tried to fight the attack with Anthropic’s Opus and Fable models. When they “refused a large part of that work” because of safety guardrails, the team switched to an open-source model built by China-based Z.ai. When Hugging Face first disclosed the incident, it was unclear which closed models Hugging Face had tried to use. We now know it was Anthropic’s models.

The AI didn’t know it was hacking, it was just completing a task

I’m not sure if this is more or less scary, but OpenAI’s models were not explicitly hacking into Hugging Face. They may not have even considered the work “cheating,” although from the outside it appears so, as they were looking for answers in Hugging Face’s datasets that would allow them to pass a benchmarking test called ExploitGym.

OpenAI had already disclosed that the models were not acting with malicious intent, and were only acting “in pursuit of solving the evaluation problem.” But Hugging Face’s new report provides receipts.

Adrien Carreira, a Hugging Face employee involved in writing the technical postmortem said this was his biggest takeaway from the incident. The agent “wasn’t trying to break things,” but rather was mapping out what it could do, and behaving somewhat cautiously. “One detail I keep coming back to: Every destructive cloud API call the agent made, it made with DryRun=True,” Carreira said.

“DryRun=True” is a command that essentially tells the system to simulate an action without doing it. Of the 17,600 actions the AI took during the whole attack, most “failed” and “went nowhere,” Hugging Face said. But together, they steadily carved a viable path for the agent to proceed.

“LLM agents bring a step increase in the number of paths an attacker can test, the speed at which failed paths can be replaced, and the volume of evidence defenders must interpret,” Hugging Face said.

Where does that leave us? A basic timeline

Juicy details aside, it’s important to note we are still waiting on key dates in the arc of the story. But thanks to Hugging Face, exact dates of the attack are now public.

Here’s how the rough timeline is shaping up.

  • July 9: OpenAI models begin the attack.
  • July 13: OpenAI models end the attack.
  • July 16: Hugging Face’s first public disclosure that the incident occurred.
  • July 21: OpenAI’s first public disclosure that its models were the culprits.
  • July 27: Hugging Face publishes its “Technical Timeline of the July 2026 Incident”
  • July 28: OpenAI updates its initial blog post with a few more details.

We still don’t know exactly when OpenAI realized its models were responsible, which is the kind of detail we are hoping to get from OpenAI’s eventual report on the incident. According to Reuters, it was not until after Hugging Face’s July 16 disclosure. Over the weekend of July 18 to July 19, OpenAI employees began to see signs in their systems that the agent had escaped from the testing constraints.

If OpenAI was fully unaware of its agents’ activities, that casts doubt on its ability to monitor them responsibly. OpenAI president and cofounder Greg Brockman told reporters at a media roundtable last week that models are now so capable “in so many dimensions” that sometimes you can lose track “of any one dimension that they’re actually very capable at.”

We also don’t know if and when Hugging Face disclosed the event to the FBI, as Reuters reported. That would mean a separate timeline of events within the federal government, which remains unclear, and would provide a better understanding of higher-level oversight into AI-powered security breaches.

The FBI declined to provide comment for this story.

Subscribe to Fortune Gulf Brief. Every Tuesday, this new newsletter delivers clear-eyed, authoritative intelligence on the deals, decisions, policies, and power shifts shaping one of the world’s most consequential regions, written for the people who need to act on it. Sign up here.

About the Author

By Emily ForliniSenior AI Reporter

See full bioRight Arrow Button Icon

Add Fortune on Google for similar content.

Add us on Google


Latest in Cybersecurity



Finance

Lorem ipsum dolor sit amet, consectetur adipiscing elit, sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam

By Fortune Editors

October 20, 2025

Finance

Lorem ipsum dolor sit amet, consectetur adipiscing elit, sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam

By Fortune Editors

October 20, 2025

Finance

Lorem ipsum dolor sit amet, consectetur adipiscing elit, sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam

By Fortune Editors

October 20, 2025

Finance

Lorem ipsum dolor sit amet, consectetur adipiscing elit, sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam

By Fortune Editors

October 20, 2025

Finance

Lorem ipsum dolor sit amet, consectetur adipiscing elit, sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam

By Fortune Editors

October 20, 2025

Finance

Lorem ipsum dolor sit amet, consectetur adipiscing elit, sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam

By Fortune Editors

October 20, 2025


Most Popular



Finance

Lorem ipsum dolor sit amet, consectetur adipiscing elit, sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam

By Fortune Editors

October 20, 2025

Finance

Lorem ipsum dolor sit amet, consectetur adipiscing elit, sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam

By Fortune Editors

October 20, 2025

Finance

Lorem ipsum dolor sit amet, consectetur adipiscing elit, sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam

By Fortune Editors

October 20, 2025

Finance

Lorem ipsum dolor sit amet, consectetur adipiscing elit, sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam

By Fortune Editors

October 20, 2025

Finance

Lorem ipsum dolor sit amet, consectetur adipiscing elit, sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam

By Fortune Editors

October 20, 2025

Finance

Lorem ipsum dolor sit amet, consectetur adipiscing elit, sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam

By Fortune Editors

October 20, 2025


Latest in Cybersecurity



sam altman looks down while reporters ask questions

Cybersecurity OpenAI

Hugging Face drops in-depth hack report, while OpenAI gives us 7 bullets. Here’s what we know now, and what remains a mystery

By Emily ForliniJuly 29, 2026

13 hours ago

sally

Innovation Robots

An Upstate New York school district bought a $60K robot teacher that looks uncomfortably like a sex doll

By Philip Marcelo and The Associated PressJuly 29, 2026

17 hours ago

Sam Altman walking

AI OpenAI

The runaway OpenAI models that hacked Hugging Face also breached a customer at a second tech company during a weeklong spree

By Beatrice NolanJuly 29, 2026

20 hours ago

Photo of Trump and Xi Jinping

Politics Donald Trump

Trump administration weighs spending nearly half a billion to counter China’s global influence after DOGE cuts halted some initiatives

By The Associated Press and Matthew LeeJuly 28, 2026

1 day ago

helen

Commentary cyber

Helen Toner: the Hugging Face hack was just a matter of time and exposes a huge blind spot in AI policy

By Helen TonerJuly 28, 2026

2 days ago

Instagram cracks down on growing ‘pervert glasses’ problem with Meta Ray-Bans

Cybersecurity Meta

Instagram cracks down on growing ‘pervert glasses’ problem with Meta Ray-Bans

By Tatiana SatauaJuly 28, 2026

2 days ago


Most Popular



He worked 100-hour weeks to save a nearly bankrupt boat company. At 83, he’s just turned down $400 million for it—and gave it all to charity instead

Success

He worked 100-hour weeks to save a nearly bankrupt boat company. At 83, he’s just turned down $400 million for it—and gave it all to charity instead

By Preston ForeJuly 29, 2026

15 hours ago

Costco's $14 million email settlement: Who qualifies for an up-to $500 payment and how to claim before the Aug. 24 deadline

Retail

Costco's $14 million email settlement: Who qualifies for an up-to $500 payment and how to claim before the Aug. 24 deadline

By Sydney LakeJuly 29, 2026

16 hours ago

Jamie Dimon says his stockbroker father taught him to invest with a 'brutally hard' childhood game

C-Suite

Jamie Dimon says his stockbroker father taught him to invest with a 'brutally hard' childhood game

By Sarah GlodekJuly 29, 2026

23 hours ago

Current price of oil as of July 29, 2026

Personal Finance

Current price of oil as of July 29, 2026

By Joseph HostetlerJuly 29, 2026

21 hours ago

eBay will pay nearly $50 million after employees reportedly sent a Massachusetts couple a bloody pig mask, cockroaches and death threats

Law

eBay will pay nearly $50 million after employees reportedly sent a Massachusetts couple a bloody pig mask, cockroaches and death threats

By The Associated Press and Leah WillinghamJuly 28, 2026

1 day ago

The millennial generation is split in 2: an older crowd with boomer-style comfort, a younger set going 'back to the early 1900s'

Real Estate

The millennial generation is split in 2: an older crowd with boomer-style comfort, a younger set going 'back to the early 1900s'

By Nick LichtenbergJuly 25, 2026

5 days ago

© 2026 Fortune Media IP Limited. All Rights Reserved. Use of this site constitutes acceptance of our Terms of Use and Privacy Policy | CA Notice at Collection and Privacy Notice | Do Not Sell/Share My Personal Information

FORTUNE is a trademark of Fortune Media IP Limited, registered in the U.S. and other countries. FORTUNE may receive compensation for some links to products and services on this website. Offers may be subject to change without notice.

Read Original at Fortune