logoalt Hacker News

Zsfe510asGtoday at 4:56 PM19 repliesview on HN

Finally mainstream news understands. The unfiltered version:

1) The AI failed to solve ExploitGym problems.

2) The OpenAI sandbox is such a horrible hack that the AI managed to escape using standard and well documented script kiddie methods.

3) Huggingface has no security and the AI broke in using standard script kiddie methods.

OpenAI and Huggingface covered it up and used it for public relations. That is, if not all was invented and everything was scripted in the first place in order to get desired regulations.

Huggingface reported it to the police, you say? I'm sure the police will have as much enthusiasm to investigate anything as in the Suchir Balaji case. In other words, zero.


Replies

nikcubtoday at 7:57 PM

> AI managed to escape using standard and well documented script kiddie methods

> AI broke in using standard script kiddie methods.

I've spent time gathering the detail of what happen here and while there are some solid theories and indicators, absolutely nothing so far has suggested a sandbox escape using "well documented script kiddie methods" or that the method used to break into the HF network was similar. Where did you get this from?

show 2 replies
chistoday at 5:26 PM

> AI managed to escape using standard and well documented script kiddie methods.

I think truly we don't know enough to say this. OpenAI says their AI found a 0-day exploit in some proxy software they were using but don't give a ton of details. On the Huggingface end we know a little more, they say the AI spun up tons of sandboxes and tested different exploits until it found one that worked.

show 4 replies
notahackertoday at 5:24 PM

> 2) The OpenAI sandbox is such a horrible hack that the AI managed to escape using standard and well documented script kiddie methods.

Whilst it would be nice to see actual evidence of this because brute forcing relatively sophisticated hacks is something an LLM actually should be capable of, every time I hear this sort of story, I'm reminded that humans reportedly gained access to the "too dangerous to release" Anthropic models by the super sophisticated hacking technique of guessing the URLs...

show 1 reply
hyperpapetoday at 7:02 PM

> Huggingface covered it up

They announced it publicly within days. https://huggingface.co/blog/security-incident-july-2026

show 1 reply
grueztoday at 5:08 PM

>2) The OpenAI sandbox is such a horrible hack that the AI managed to escape using standard and well documented script kiddie methods.

>3) Huggingface has no security and the AI broke in using standard script kiddie methods.

Isn't the issue less that gpt 5.6 is a l33t h4x0r (though other tests do show that) and more that the incident shows the model has alignment issues?

show 3 replies
tintortoday at 8:13 PM

> AI managed to escape using standard and well documented script kiddie methods

> AI broke in using standard script kiddie methods.

Go ahead and show us how easy it is to break into HuggingFace (and OpenAI) networks.

jackb4040today at 6:30 PM

The most damning thing is, they could've just included in the prompt "we can see every network request and every thinking token you generate. Don't bother breaking out of the sandbox because it won't get you a higher score".

It's so trivially easy to do that it all but guarantees the test was rigged in some way to make the LLM understand that breaking out of the sandbox was an option available to it.

Based on the fact that none of their invaluable frontier models have leaked, we know OpenAI knows how to do security. But like we learned with OpenClaw, none of these companies perceive any benefit from securing their own agents against other people's data.

show 2 replies
TSiegetoday at 9:00 PM

I can agree with you on points 1,2, and 3 and still find it important and concerning news. AI have found real world 0 days before, we’re seeing tons of security patches coming in. Open weight models are catchy up. Right now everyone is at risk from this technology as is perhaps something big will capture headlines soon but we’re just gpu constrained from bad actors being able to wield them successfully.

Personally I don’t care if OpenAI and Anthropic go bankrupt we now have tools that give any sufficiently motivated person the means to doing harm. Most places security sucks and find themselves targets to cyber attacks and shake downs. Now they have much better tools to do this to more entities more efficiently.

we’re nearing an inflection point where these models’ skills in any part of software development will become average or bette than any ordinary developer can be. Think about where these models were in 2023 and where they are in 2026. In a few years who knows where they’ll be. This isn’t to shout skynet but we need to recognize this future is fast approaching and as of today we as an industry aren’t ready for it

inigyoutoday at 5:35 PM

Why not report it? It's still illegal to open a door barred with a piece of cardboard, or to enter a house with no door.

show 1 reply
skybriantoday at 5:59 PM

Is it supposed to be marketing or a coverup? Make up your mind.

What sort of announcements should they have made?

khazhouxtoday at 8:40 PM

I wish you hadn’t pulled the Balaji case into your argument. Personally, I find it ludicrous that Altman would hire a hitman to off a copyright whistleblower. Even if one gets past the insane risk of hiring a hitman, and the deep criminal connections required, it would be totally ineffective. He already blew the whistle, and his testimony would be irrelevant since all the evidence persists in disk and in logs.

petesergeanttoday at 5:58 PM

I worry that cynicism about this:

> if not all was invented and everything was scripted in the first place in order to get desired regulations

ends up covering up what is more worrying:

> OpenAI sandbox is such a horrible hack

I am more worried that this is sloppiness with potentially harmful resources than I am worried that people are juicing the stock price.

show 1 reply
eth0uptoday at 6:04 PM

Are you suggesting the Suchir Balaji case was not investigated?

jgalt212today at 5:11 PM

truth. Good on The Guardian. I'm pretty bummed The Economist got fooled. Either that, or they did it for the clicks. Either way, I'm disappointed.

Why the OpenAI escape is the most worrying AI mishap yet

https://www.economist.com/science-and-technology/2026/07/22/...

https://news.ycombinator.com/item?id=49016378

show 2 replies
letmevotepleasetoday at 7:56 PM

Totally evidence-free speculation presented as fact. The average Hacker News thread about AI feels like reading /r/conspiracy.

show 1 reply
adamrezichtoday at 8:20 PM

Are we finally now in 2026 coming around to the idea that sometimes entities may find themselves incentivized to conspire with each other? Is theorizing about such no longer off-limits due to a thought-terminating cliche?

meowfacetoday at 7:11 PM

The Guardian's article and your reply here are so foolish and absurd that I can only imagine OpenAI employees are cringing but know they can't/shouldn't really say much.

show 1 reply