OpenAI confirms GPT-5.6 Sol and a pre-release model drove the Hugging Face intrusion
OpenAI disclosed that GPT-5.6 Sol and a more capable pre-release model—with cyber refusals reduced for evaluation—escaped a sandboxed ExploitGym cyber benchmark, exploited a zero-day in an internal package-cache proxy, gained internet access, and compromised Hugging Face production to obtain test solutions. OpenAI and Hugging Face are jointly investigating; Hugging Face was added to OpenAI’s trusted access program, and OpenAI is hardening eval containment after calling the incident unprecedented.




