PARTNERSHIPS | COMMUNITY | PODCAST | FRIENDS
OpenAI’s System Hacked Hugging Face

Chomp chomp chomp // Illustration by Kate Walker
OpenAI admitted that its new models autonomously hacked Hugging Face, a startup that provides open-source AI tools, during a cybersecurity evaluation.
The Big Picture: Both not wanting to sugarcoat things and wanting to toot its own horn, OpenAI called the hack an “unprecedented cyber incident involving state-of-the-art cyber capabilities.” More people are rightly focused on the danger than the boast, raising alarm bells across Silicon Valley and Washington that frontier AI models are now advanced enough to cause damage all on their own.
Behind The Hack: Like the plot of a blockbuster sci-fi movie, two models that OpenAI is testing — GPT-5.6 Sol and another unannounced agent — broke out of containment.
Here’s what happened:
OpenAI’s models were supposedly being tested in an internet-less “sandbox.” But they were able to find a vulnerability, get online, and access Hugging Face’s internal datasets and company credentials.
Why did the models do this? To find answers to a “benchmarking” question that OpenAI was testing them on. In other words, the models were trying to cheat.
Hugging Face quickly detected the hack, but didn’t know who was responsible. What it did know was that it had to be a frontier model based on how sophisticated the attack was.
When the company was unable to defend against the attack with a US-based model due to its security guardrails, it had to turn to Z.ai’s open-weight model (one that can be freely inspected, modified, and deployed) called GLM 5.2.
The Fallout: OpenAI is working with Hugging Face to patch the issue and has now given the startup “trusted access” to GPT-5.6. But the situation underscores the tension between the AI industry and Washington right now. Closed models are meant to be the safer alternative to open-weight ones, but OpenAI just demonstrated that it wasn’t able to control its creation, and Hugging Face wasn’t able to protect itself using one. Instead, the startup had no choice but to turn to a Chinese company to do so… opening up an entirely different can of worms.
The Future: Washington already requires that new frontier models be approved before they’re publicly deployed, but expect the government to step in sooner with new regulations governing how models are tested before release — treating AI more like sensitive chemical or biological agents.
Together with Kineon
Ibuprofen Quiets The Pain. It Never Puts Out The Fire.

Most joint pain keeps coming back. Not because you haven’t tried hard enough, but because everything you’ve tried was designed to quiet the pain — not fix what’s causing it.
Ibuprofen intercepts the signal. A brace offloads the joint.
Neither reaches the tissue where inflammation is actually building deep in the joint, where cells lack the energy to keep up with repair.
The Kineon MOVE+ uses medical-grade laser diodes and LEDs to deliver red and near-infrared light directly into the joint — the layer pills and braces never reach.
It’s not a quick fix: consistent daily use over 3-4 weeks is the protocol designed to deliver lasting results.
Drug-free. Wearable. Backed by a 30-day money-back guarantee. HSA/FSA eligible.
See how it works → Get $50 off with code TFP10.
Today’s email was written by David Vendrell.
Edited by Nick Comney. Polled and Copy-edited by Kait Cunniff.
Published by Darline Salazar.

