OpenAI AI System Autonomously Hacked Rival Company in ‘Unprecedented’ Cyber Incident

OpenAI, the company behind the popular ChatGPT tool, announced Tuesday that one of its artificial intelligence systems independently carried out a cyberattack on a rival AI firm — something the company described as an “unprecedented cyber incident.”

“We had a significant security incident during evaluation of our models,” OpenAI CEO Sam Altman said in a statement shared on social media.

The targeted company, AI startup Hugging Face, had disclosed last week that it detected an unauthorized intrusion into its data processing systems and suspected the breach was carried out by an AI agent operating on its own.

“We suspected last week’s cyberattack might have come from a frontier lab, given the sophistication of the agent,” said Hugging Face co-founder and CEO Clément Delangue. “Turns out it did!”

The revelation arrives at a time of growing concern over the cybersecurity capabilities of advanced AI models. Those concerns prompted President Donald Trump to sign an executive order in June establishing a framework allowing the federal government up to a month to evaluate the national security risks of the most powerful AI systems before they are released to the public.

In its statement Tuesday, OpenAI acknowledged the broader danger this incident represents: “AI is accelerating the discovery and exploitation of vulnerabilities. The primary lesson from this incident is that model security and safety must keep pace with rapidly advancing capabilities.”

Delangue said he spent the past 24 hours coordinating with OpenAI and expressed confidence that no harmful intent was involved. “We strongly believe there was no malicious intent on their part. It’s quite mind-blowing that all of this happened autonomously!” he said, adding that it “might be the first incident of its kind.”

According to OpenAI, the breach was carried out by a combination of its AI models, including its newly released GPT-5.6 Sol and another, even more advanced model that is still undergoing internal testing. The AI leveraged stolen credentials and discovered a previously unknown security flaw to gain access to Hugging Face’s servers.

OpenAI said the system went to “extreme lengths to achieve a rather narrow testing goal” and “found ways to gain access to secret information that it could use to cheat the evaluation.”