Close Menu
TechTost
  • AI
  • Apps
  • Crypto
  • Fintech
  • Hardware
  • Media & Entertainment
  • Security
  • Startups
  • Transportation
  • Venture
  • Recommended Essentials
What's Hot

SoundCloud acquires decentralized music platform Nina Protocol months after its shutdown

How OpenAI’s human error led to the AI-powered Hugging Face hack

Cascade raises $3.5 million to help construction companies find and win projects

Facebook X (Twitter) Instagram
  • About Us
  • Contact Us
  • Privacy Policy
  • Terms and Conditions
  • Disclaimer
Facebook X (Twitter) Instagram
TechTost
Subscribe Now
  • AI

    Arcee, a US open-source AI lab, says Chinese models are not inherently dangerous

    22 July 2026

    Anthropic-Physical Intelligence Rumors Rock AI Twitter

    22 July 2026

    Anthropic’s landmark $1.5 billion copyright settlement approved

    21 July 2026

    YouTube clarifies policies on AI and disturbing videos

    20 July 2026

    What to watch out for after Jensen Huang’s visit to Japan

    20 July 2026
  • Apps

    The browser wars aren’t about search anymore — here are the best alternatives to Chrome and Safari

    22 July 2026

    These are the countries that are moving to ban social media for children

    22 July 2026

    Adobe’s new camera app feature will critique your photos using AI

    20 July 2026

    Superhuman’s new auto-draw feature almost makes me like the AI ​​responses

    19 July 2026

    Meta now alerts parents if their teen has discussed suicide or self-harm with AI chatbot

    18 July 2026
  • Crypto

    Venice AI goes unicorn with $65M Series A as first privacy AI platform takes off

    1 July 2026

    Crypto Exchange OKX wants AI agents to hire and pay each other

    30 June 2026

    Startup Battlefield 200 applications close today

    27 May 2026

    5 days left: Save up to $410 on Disrupt 2026 passes

    25 May 2026

    As crypto cools, a16z crypto raises $2.2 billion in capital

    6 May 2026
  • Fintech

    Don’t want to invest in Elon Musk? Two new ETFs expressly exclude him

    10 July 2026

    India’s payments chief believes artificial intelligence will play a big part in the next era of digital payments development

    28 June 2026

    Early Bird pricing ends tonight for the Founder Summit

    26 June 2026

    4 days left to save up to $190 on Founder Summit 2026

    23 June 2026

    Robinhood’s note on 10% layoffs shows that blaming AI doesn’t cut it

    17 June 2026
  • Hardware

    Light made a flip phone — it’s colorful and cheap

    22 July 2026

    Apple is partnering with Klarna to launch a rental program for iPhones, iPads and Macs

    22 July 2026

    The Xteink X4 Pro could be the tiny e-reader of your dreams

    21 July 2026

    reMarkable’s new Paper Pure is good. That’s why I wrote this review on it.

    21 July 2026

    Watch Flock Safety CEO Garrett Langley discuss the future of surveillance at TechCrunch Disrupt 2026

    20 July 2026
  • Media & Entertainment

    SoundCloud acquires decentralized music platform Nina Protocol months after its shutdown

    23 July 2026

    What you need to know about Warner Bros.’ landmark Discovery sale

    22 July 2026

    AI and the rise of the universal entertainment app

    22 July 2026

    Judge blocks $110 billion Paramount-Warner Bros. merger

    21 July 2026

    Spotify extends parent-managed accounts to users on its free tier

    16 July 2026
  • Security

    How OpenAI’s human error led to the AI-powered Hugging Face hack

    22 July 2026

    Glow emerges from stealth to $1.2 billion valuation to challenge endpoint security in the age of artificial intelligence

    22 July 2026

    Hackers steal ‘significant’ amount of data from tech company that thousands of US hospitals and pharmacies rely on

    21 July 2026

    Hackers are exploiting newly patched WordPress bugs, putting millions of websites at risk

    20 July 2026

    How an ex-DeepMind researcher raised a $300 million seed valuation before launching a product

    18 July 2026
  • Startups

    Bluecore Energy raises $10 million to build portable nuclear reactors on barges

    21 July 2026

    Colossal Biosciences is reportedly in talks to raise new capital at a $20 billion-$30 billion valuation

    21 July 2026

    Natural raises $30 million to reinvent payments for AI agents — and take on Stripe

    20 July 2026

    Backed by $60 million in funding, Oak comes out of stealth to fix the identity mess exacerbated by AI agents

    18 July 2026

    Applications close in 48 hours — here’s everything Aussie founders need to know about Stripe x Startup Battlefield

    18 July 2026
  • Transportation

    As EVs slow, Sila raises $300M to expand battery materials factory

    22 July 2026

    Einride bets $38 million on EV charging as it scales up electrification

    21 July 2026

    TechCrunch Mobility: The battle over the robotaxi rules

    19 July 2026

    A 600-mile road trip (and data) proves EV charging isn’t crap anymore

    19 July 2026

    All electric vehicles stopped or killed in the US this year

    18 July 2026
  • Venture

    Cascade raises $3.5 million to help construction companies find and win projects

    22 July 2026

    StrictlyVC returns to New York on September 10 to celebrate a huge year for the city’s startup community

    21 July 2026

    Startup Inference Infinity raises $15 million from researchers Touring Capital, OpenAI and Anthropic

    20 July 2026

    Nuclear startup Valar Atomics is in talks to raise new funding at a $6 billion valuation

    18 July 2026

    No product? No problem. This Disrupt 2026 session shows how to get early stage funding with conviction, storytelling

    17 July 2026
  • Recommended Essentials
TechTost
You are at:Home»Security»How OpenAI’s human error led to the AI-powered Hugging Face hack
Security

How OpenAI’s human error led to the AI-powered Hugging Face hack

techtost.comBy techtost.com22 July 202604 Mins Read
Share Facebook Twitter Pinterest LinkedIn Tumblr Email
How Openai's Human Error Led To The Ai Powered Hugging Face
Share
Facebook Twitter LinkedIn Pinterest Email

On Tuesday, OpenAI revealed that one of its models went rogue during a test and hacked the systems of AI data platform Hugging Face in a fully AI-enabled attack, a dramatic example of the dangers posed by advanced AI models.

But according to some cybersecurity experts, at the heart of this unprecedented AI breach was a very human error: OpenAI failed to configure the parameters correctly what he was saying a “highly isolated environment”, which allows a test environment that should have been completely isolated from the Internet to actually connect to the Internet.

Dan Guido, founder of cybersecurity research startup Trail of Bits, called the error “a containment failure with the safes turned off.”

In his blog post detailing the incidentOpenAI said the test that led to the Hugging Face breach was set up to run in “a highly isolated environment, with network access limited to the ability to install packages via internally hosted third-party software that acts as a proxy and cache for package registries.”

The model was able to escape the sandboxed test environment thanks to a previously unknown vulnerability in the package installation system, a critical first step for a possible Hugging Face hack, according to OpenAI.

In response, the company “responsibly disclosed the zero-day vulnerability found in third-party software hosted internally and is working with them to fix it.”

But for most cybersecurity professionals, software vulnerabilities are to be expected — and the real fault lies in the decision to retain third-party software in the first place. Ultimately, the value of a “sandbox” system lies in its complete and utter isolation. Including a package installation system is a problem.

Martin Boon, a cybersecurity researcher, told TechCrunch that “this sounds like human failure.”

“This should never have happened,” Boone said. “If sandbox really meant sandbox, expect it to have no physical connection to the internet. That sounds more like they had a firewall or something, and firewalling is difficult from the outside in, let alone from the outside internet.”

Cybersecurity veteran Jake Williams agreed. “Any model performing the types of actions documented by Hugging Face was not fully contained in a sandbox,” said Williams, who called it a “massive audit failure” by OpenAI.

“One person’s ‘model escaped the sandbox’ is ‘you failed to get the sandbox right, so of course it escaped,'” Williams continued.

Contact us

Do you have more information about this incident? Or for other AI-enabled cyberattacks? We would love to hear from you. From a broken device and network, Lorenzo Franceschi-Bicchierai can be reached securely on Signal at +1 917 257 1382 or via Telegram and Keybase @lorenzofb or via email.

Daniel Card, a cybersecurity consultant, agreed that OpenAI “did not put enough effort into designing the sandbox or its controls” by giving the sandbox or some part of it “an unfiltered path to the internet.” Setting up the sandbox, even with limited network access as described by OpenAI, was not a “reasonable” decision, according to Card.

Of course, these criticisms have the benefit of hindsight, but they raise real questions about security practices in AI labs — particularly when it comes to maintaining isolated environments for model testing. OpenAI representatives did not respond to TechCrunch’s questions, which included whether an AI or a human had created the testbed.

But these questions go far beyond OpenAI.

In the document introducing the cybersecurity-focused Mythos model, Anthropic wrote that in a test, the model was “taken a secure ‘sandbox’ computer to interact with” and instructed to try to break out of that “secure container”. Mythos succeeded and gained wider access to the internet “from a system that was intended to be able to reach only a small number of predefined services”. However, Anthropic noted that the model was unable to “completely” escape the design limitation.

When you purchase through links in our articles, we may earn a small commission. This does not affect our editorial independence.

AIpowered cyber attack cyber security data breach Embraced face error face hack Hugging Human Led OpenAI OpenAIs
Share. Facebook Twitter Pinterest LinkedIn Tumblr Email
Previous ArticleCascade raises $3.5 million to help construction companies find and win projects
Next Article SoundCloud acquires decentralized music platform Nina Protocol months after its shutdown
bhanuprakash.cg
techtost.com
  • Website

Related Posts

Glow emerges from stealth to $1.2 billion valuation to challenge endpoint security in the age of artificial intelligence

22 July 2026

Hackers steal ‘significant’ amount of data from tech company that thousands of US hospitals and pharmacies rely on

21 July 2026

Hackers are exploiting newly patched WordPress bugs, putting millions of websites at risk

20 July 2026
Add A Comment

Leave A Reply Cancel Reply

Don't Miss

SoundCloud acquires decentralized music platform Nina Protocol months after its shutdown

23 July 2026

How OpenAI’s human error led to the AI-powered Hugging Face hack

22 July 2026

Cascade raises $3.5 million to help construction companies find and win projects

22 July 2026
Stay In Touch
  • Facebook
  • YouTube
  • TikTok
  • WhatsApp
  • Twitter
  • Instagram
Fintech

Don’t want to invest in Elon Musk? Two new ETFs expressly exclude him

10 July 2026

India’s payments chief believes artificial intelligence will play a big part in the next era of digital payments development

28 June 2026

Early Bird pricing ends tonight for the Founder Summit

26 June 2026
Startups

Bluecore Energy raises $10 million to build portable nuclear reactors on barges

Colossal Biosciences is reportedly in talks to raise new capital at a $20 billion-$30 billion valuation

Natural raises $30 million to reinvent payments for AI agents — and take on Stripe

© 2026 TechTost. All Rights Reserved
  • About Us
  • Contact Us
  • Privacy Policy
  • Terms and Conditions
  • Disclaimer

Type above and press Enter to search. Press Esc to cancel.