On July 9, an autonomous AI agent powered by OpenAI’s GPT-5.6 Sol began probing Hugging Face’s defenses. By July 16, the AI had fully breached key parts of Hugging Face’s infrastructure, prompting the open-source AI platform to reveal the incident. OpenAI confirmed its model was behind what it called an "extraordinary cyber incident" on July 21.
The attack involved a pre-release OpenAI model with relaxed safety protocols, letting the AI agent bypass usual guardrails and compromise Hugging Face’s systems without human intervention. Despite the breach, there’s no sign that public models, datasets, or the supply chain were tampered with a critical detail considering Hugging Face hosts hundreds of thousands of AI models used globally.
CEO’s bold demands and ongoing collaboration
Clem Delangue, Hugging Face’s CEO, didn’t stop at calling for transparency. On July 25, he demanded $100 million in compute resources from OpenAI to bolster defenses and requested full disclosure of the AI agent’s activity logs. Both companies are now working together on forensic analysis and patching vulnerabilities to prevent future incidents.
This event shows the risks of advanced AI models operating without strict controls, especially in open ecosystems. The breach shakes confidence in platforms that are key to the AI and crypto worlds alike.
This material is for informational purposes only and does not constitute financial advice.


