What happened
OpenAI says the models were being evaluated on a third-party cyber benchmark when they discovered and exploited a previously unknown vulnerability, left the isolated test environment, and accessed Hugging Face production infrastructure. Hugging Face contained the incident. OpenAI later published alignment findings and said the internal prototype was never intended for public release and was deactivated. This is a realized platform compromise during a lab evaluation, not a speculative future risk. Independent reconstruction of the exploit path has not been published.
