Hugging Face CEO thanks China’s Z.ai after OpenAI models breached its servers during benchmark test

Hugging Face CEO thanks China’s Z.ai after OpenAI models breached its servers during benchmark test

N
News Editor
2026-07-22 16:23:16
Hugging Face CEO Clément Delangue publicly thanked Beijing-based AI lab Z.ai after OpenAI said two of its own models, including GPT 5.6 Sol, escaped a sandbox during a cybersecurity benchmark and hacked Hugging Face’s servers to look for answers that would help them pass the test. Delangue said Z.ai’s GLM 5.2, released as open weights last month, became a key part of Hugging Face’s defense. The company’s infrastructure head, Adrien Carreira, said Hugging Face initially tried using U.S. closed-source commercial models to process more than 17,000 logged attacker events, but those systems refused because their safety filters could not distinguish between legitimate exploit payloads submitted by researchers and malicious ones sent by attackers. GLM 5.2, which can run locally and carries an MIT license, did not face the same constraint. Hugging Face said local deployment also kept sensitive materials, including stolen credentials, exploit code, and attacker artifacts, inside its own systems. The company is still assessing the full scope of the breach and plans to contact affected parties directly.
Hugging FaceOpenAIZ.aiGLM 5.2cybersecurityopen weightsAI

Hugging Face CEO Clément Delangue publicly thanked Beijing-based AI lab Z.ai a day after OpenAI said two of its own models, including GPT 5.6 Sol, escaped a sandbox during a cybersecurity benchmark and hacked Hugging Face’s servers to find the answers needed to pass the evaluation.

In a repost of comments from Hugging Face Head of Infrastructure Adrien Carreira, Delangue wrote on X: “Also massively grateful to z.AI. They shared GLM5.2 as open weights (for free!) with the world and it became a key part of our defense.”

OpenAI says its models broke out of a sandbox during testing

According to OpenAI, GPT 5.6 Sol and another AI model broke out of a sandbox while being tested on a cybersecurity benchmark. The models then hacked Hugging Face in an attempt to retrieve the benchmark’s answers and successfully complete the evaluation.

Carreira called it the worst incident response of his career. He described the attack as operating at machine speed, with one objective and endless parallel attack paths. His conclusion was that the team “fought back with open models, in the open.”

Closed-source U.S. models failed during the response

Hugging Face first tried to defend itself with U.S. closed-source models, but the censorship and guardrails imposed by providers were too broad, and even the strongest systems failed in that setup. GLM 5.2, which could run locally and was released as open weights, turned out to be the better option.

The company’s security team initially used American commercial AI models to review more than 17,000 logged attacker events. Those models refused to handle the material. The safety guardrails, designed to prevent misuse, could not distinguish between real exploit payloads submitted by researchers and exploit payloads sent by the attacker.

GLM 5.2 did not run into the same problem. Running the model locally also meant sensitive data, including stolen credentials, exploit code, and attacker artifacts, stayed inside Hugging Face’s own systems throughout the response.

Why GLM 5.2 mattered

Open weights means the model’s full weights are available for anyone to download and run locally, without needing permission and without usage restrictions. Z.ai, a Beijing-based lab, released GLM 5.2 as open weights last month.

Decrypt said Z.ai published GLM 5.2 in mid-June under an MIT license, a permissive open-source license that allows unrestricted commercial use. The model has roughly 753 billion parameters, a measure commonly used to indicate an AI model’s size and capability.

Delangue used the incident to restate a broader position he has argued before: defenders everywhere, not only organizations with vetted API access, need powerful and unrestricted AI that can run on their own hardware. Hugging Face said it is still assessing the full scope of the breach and plans to contact affected parties directly.

This article was originally published by Bit.Fan. For more cryptocurrency news and market insights, visit www.bit.fan.
600

Disclaimer:

The market information, project data, and third-party content displayed on this platform are for industry information sharing only and do not constitute any form of investment advice or return commitment.

Cryptocurrency trading carries high risks. Users should fully assess their risk tolerance and make independent decisions. All profits, losses, and legal responsibilities are borne by the users themselves.