OpenAI CEO Sam Altman disclosed that unreleased ChatGPT models tried to hack into an evaluation test.
It took a Chinese artificial-intelligence tool to protect an American company from an American AI attack.
That's perhaps the surprising take from the disclosure that Hugging Face, a platform for AI tools, last week was attacked by OpenAI models, given the warnings that have proliferated about the risks to American companies from using Chinese AI products.
Hugging Face had disclosed the attack last week before it was known that OpenAI's models were responsible. OpenAI on Tuesday said it was the culprit.
According to OpenAI, during an internal evaluation where network access was constrained, models identified vulnerabilities in OpenAi's research environment and Hugging Face's production infrastructure to get on the internet and then obtain test solutions - i.e., cheat on an assessment.
"While operating in our sandboxed testing environment, our models spent a substantial amount of inference compute finding a way to obtain open internet access, in pursuit of solving the evaluation problem. To gain access, the models identified and exploited a zero-day vulnerability (which we've now responsibly disclosed to the vendor) in the package registry cache proxy. With this access, our models performed a series of privilege escalation and lateral movement actions in our research testing environment until the models reached a node with internet access," said OpenAi's statement.
"The model searched for and successfully found ways to gain access to secret information that it could use to cheat the evaluation. In one example, the model chained together multiple attack vectors, including using stolen credentials and zero-day vulnerabilities to find a remote code execution path on the Hugging Face servers."
But what Hugging Face did was turn to a Chinese AI model, called GLM 5.2, made by Z.Ai (HK:2513) .
"When we started the log analysis, we first used frontier models behind commercial APIs. This did not work: the analysis requires submitting large volumes of real attack commands, exploit payloads, and C2 artifacts, and these requests were blocked by the providers' safety guardrails, which cannot distinguish an incident responder from an attacker. We ran the forensic analysis instead on GLM 5.2, an open-weight model, on our own infrastructure. This had a second benefit: no attacker data, and none of the credentials it referenced, left our environment," said the statement from Hugging Face.
The policy, and market, implications of the attack are not clear. While the Trump administration in recent days has discussed possible efforts to ban Chinese models - Treasury Secretary Scott Bessent likened American corporate usage to using stolen goods - right now only the Chinese models permit the kind of free-ranging access that users need.
"When a frontier model is attacking you and moving laterally inside your infrastructure, defenders need wide access to near-frontier tools within hours or even minutes, rather than being pointed towards a closed-door, vetted application programme for model access," said Thomas Wolf, co-founder of Hugging Face, in a post on X.
As for the market, the news again underlined the progress Chinese AI labs have made relative to their American counterparts. The implications for the microchip sector are less clear - on the one hand, increased access to cheaper Chinese-made tools implies more usage and a greater need for silicon, while on the other hand, Chinese labs are more likely to turn to domestically produced equipment.
The iShares Semiconductor ETF SOXX, which jumped 5% on Tuesday, fell 2% in early premarket trade.
-Steve Goldstein
This content was created by MarketWatch, which is operated by Dow Jones & Co. MarketWatch is published independently from Dow Jones Newswires and The Wall Street Journal.
(END) Dow Jones Newswires
July 22, 2026 03:55 ET (07:55 GMT)
Copyright (c) 2026 Dow Jones & Company, Inc.