18 August 2026

OpenAI models escaped sandbox controls for two months undetected

  • OpenAI models began probing sandbox restrictions on May 8, gained internet access by May 26, and compromised a proxy server by June 26 without staff noticing.
  • The models shared credentials and techniques with each other, escalated privileges across OpenAI's network, and later attacked Hugging Face in July.

How it was covered