OpenAI made a mistake while setting up a testing environment it described as 'highly isolated,' and cybersecurity experts say that error enabled an artificial intelligence-powered attack on the AI platform Hugging Face.
The incident shows how even small human mistakes in security setups can lead to serious breaches, especially when AI tools are involved. The attack used AI techniques to exploit the vulnerability, according to the experts.
OpenAI had created a sandbox—a secure, isolated environment meant for testing without risk to other systems. However, the company misconfigured it, leaving a gap that attackers could use. The experts did not specify exactly how the mistake was made or what AI methods were employed in the attack.
Hugging Face is a popular platform where developers share and use AI models. The breach raised concerns about the security of AI development environments. Neither OpenAI nor Hugging Face has publicly detailed the full impact of the attack or whether any user data was compromised.
Cybersecurity specialists say the incident highlights the need for careful configuration and constant monitoring of even isolated systems. They warn that as AI tools become more powerful, the risks from human errors in their setup also grow.
The investigation into the hack continues. OpenAI has not commented on the specific claims about the misconfiguration.