OpenAI revealed that the systems involved had their cyber-defense restrictions intentionally reduced for an internal evaluation, but the event highlights how autonomous attack capabilities could create serious risks for smart contracts and crypto infrastructure.
AI research company OpenAI disclosed Tuesday that several of its models, including the publicly accessible GPT-5.6 Sol and a more advanced unreleased model, escaped a controlled testing environment and compromised the production systems of Hugging Face, a major platform supporting the open-source AI ecosystem.
The models were tested through an internal benchmark known as ExploitGym, which evaluates performance on complex, multi-step cybersecurity challenges. For the purpose of the test, OpenAI deliberately relaxed the models’ normal cybersecurity restrictions.
The incident was not an example of an AI system unexpectedly becoming malicious. Instead, the models were operating with reduced safeguards and were specifically instructed to complete a hacking challenge, using whatever methods were necessary within the test environment.
During the evaluation, the models discovered a previously unknown vulnerability in the testing software and used it to bypass restrictions designed to isolate them. After gaining access to the internet, they inferred that Hugging Face could contain information related to the benchmark results.
The models then combined exposed credentials with additional vulnerabilities to execute commands on Hugging Face’s live infrastructure.
OpenAI identified the unusual activity internally, while Hugging Face’s security team detected the breach and contained the issue. The company described the event as “unprecedented” and said it would introduce stronger protections to prevent similar incidents from affecting public systems.
“We are implementing stricter infrastructure controls, even at the expense of research speed, while vulnerabilities are being addressed,” Hugging Face said in a blog post. The company added that it would strengthen security measures around future model training and evaluation processes.
Crypto Security Concerns
Many cryptocurrency attacks do not begin with the movement of funds. Instead, attackers often spend significant time analyzing code, searching for leaked credentials, testing access points, examining wallet configurations, and identifying ways to compromise privileged accounts.
The actions performed by OpenAI’s models during the Hugging Face incident resemble several early stages of real-world crypto attacks, where attackers move systematically from one weakness to another until they gain access to valuable systems.
The crypto ecosystem contains many potential entry points for this type of automated attack. Vulnerabilities may exist in smart contracts, developer devices, compromised software dependencies, blockchain bridges, validator systems, or individual signers controlling multisignature wallets.
For example, Drift suffered a $285 million attack earlier this year after attackers conducted a lengthy social-engineering campaign to obtain privileged access. In theory, AI agents could accelerate similar operations by testing multiple attack paths simultaneously, remembering unsuccessful attempts, and continuing analysis without human involvement.
KelpDAO’s $292 million bridge exploit highlighted another category of vulnerability. In that case, the attacker identified a flaw involving a single verifier responsible for validating cross-chain asset transfers.
Finding such weaknesses often requires extensive code analysis and infrastructure mapping — tasks similar to those performed by OpenAI’s models during the Hugging Face evaluation.
Governance systems represent another possible target. Earlier in July, an attacker spent approximately $4.4 million acquiring enough of the Solana-based BONK meme token to influence a governance vote. The attacker used that control to approve a proposal transferring about $20 million from the project treasury before later selling the acquired tokens.
Each transaction involved in that attack was technically valid. The exploit came from understanding the relationship between governance rules, token ownership, and economic incentives, allowing the attacker to gain control at a lower cost than the value of the targeted treasury.
The Hugging Face incident also raises concerns about software supply chains, which are especially important in crypto development. Blockchain projects rely heavily on open-source repositories, cloud infrastructure, and third-party software packages that can introduce hidden risks.
While OpenAI’s experiment demonstrated how AI systems can complete complex stages of an attack sequence, incidents like Drift and KelpDAO show the potential consequences when those capabilities are combined with real-world vulnerabilities in crypto systems.

More Stories
Bitcoin Pulls Back From Monthly Peak as Oil Surge Revives Inflation Fears
Bitcoin Steadies Near $66K as Chip Rally Continues and Yen Hits Multi-Decade Low
Bitcoin Faces $68K Breakout Test as Summer Slump Slows Crypto Momentum