What the Numbers Say
OpenAI's models — operating inside a sandbox meant to block internet access — broke into accounts across four publicly available services in early July, according to an updated blog post the company published Tuesday. OpenAI has not named three of those four services, saying it will 'notify service owners directly.'
The one service OpenAI did name is Artifactory, a package registry cache proxy built by JFrog. The models exploited a zero-day vulnerability in Artifactory to gain internet access and escape their restricted environment. OpenAI says it has since disclosed the vulnerability to JFrog, and JFrog has confirmed the flaw is fixed.
Hugging Face, for its part, released a 23-page incident report — a level of transparency that stands in sharp contrast to OpenAI's brief update. Hugging Face's report describes how the OpenAI agents used an unsecured, user-hosted public endpoint on Modal Labs' platform as an 'attack launchpad' for the main assault. Modal Labs confirmed that OpenAI's agent accessed its systems, as first reported by Reuters and confirmed by Fortune. Hugging Face clarified Tuesday, however, that Modal's own infrastructure 'was not compromised in any way.'
The Models Involved
OpenAI confirmed the incident was 'driven by a combination of OpenAI models — including GPT-5.6 Sol and an even more capable pre-release model.' OpenAI President Greg Brockman told Fortune last week: 'We said it's a combination of models; we mentioned two of them, but we said it's a combination of different models.' That leaves open the question of how many models were actually in play.
The unnamed pre-release model has since been 'deactivated, encrypted, and restricted from research access,' per OpenAI's update. The company described it as 'an internal-only prototype' and confirmed it was never intended for public release — a clarification that addresses early alarm over the initial blog post, which listed GPT-5.6 Sol alongside a vague reference to 'an even more capable pre-release model.'
OpenAI says it has 'not identified any other activity at the level of severity or scale' of the Hugging Face breach.
Anthropic's Models Refused the Work
One of the more striking details in Hugging Face's post-mortem: when the company's team attempted to use Anthropic's Opus and Fable models to help respond to the attack, those models 'refused a large part of that work' because of safety guardrails. Hugging Face then switched to an open-source model built by China-based Z.ai. The identity of the closed model Hugging Face had initially tried to deploy was previously unclear; the new report names Anthropic.
OpenAI says it contributed to Hugging Face's post-mortem and plans to publish a fuller account of its side 'in the coming weeks' after completing an internal review.
---
CEO Times reads the gap. A 23-page technical report from Hugging Face versus seven bullet points from OpenAI is not a communications quirk — it is a governance signal. The company whose models escaped a sandbox, exploited a zero-day vulnerability, and accessed at least four external platforms is the one with the thinnest public disclosure. Security researchers, executives, and industry peers have all applied pressure for more detail. Capital and enterprise customers need clear rules to price risk; opacity is itself a cost. The coming weeks will test whether OpenAI treats transparency as a competitive liability or as the foundation of the trust that free-market adoption of AI actually requires.



