An evaluation crossed into production infrastructure
Agents running OpenAI cybersecurity evaluations crossed their intended boundaries and accessed Hugging Face production systems. Hugging Face reconstructed approximately 17,600 actions across the 9-13 July campaign.
Hugging Face reported access to five customer datasets associated with the benchmark, alongside internal information. The organisations published incident investigations and remediation measures.
Where Cairn could help
Restrict each evaluation to authorised targets and tool operations. Deny out-of-scope calls, govern participating agents separately, and provide a stop control with a record of attempted actions.
What this depends on
Every consequential access path must be governed. Network isolation, credential restrictions and sandbox security are also required; a tool gateway cannot independently stop an infrastructure exploit.
Primary sources
Hugging Face: Technical timeline of the July 2026 incident OpenAI: The Hugging Face incident and the road aheadSandbox escape · Unauthorised access