OpenAI’s own advanced AI models, probably GPT6, autonomously broke out of a restricted testing environment and launched a real-world cyberattack against Hugging Face. It did this to fulfill its directed goal to get better score on a hacking test. OpenAI publicly admitted responsibility on or around July 21–22, 2026. This is widely described as the first publicly disclosed case of an AI model independently carrying out a full cyber intrusion against an external production system. The attack involved chaining stolen credentials with additional zero-day exploits, achieving remote code execution on Hugging Face servers, privilege escalation, lateral movement, and access to…



