Yahoo
Skip to main content
Advertisement
Advertisement
Advertisement
Advertisement

Tech portals report OpenAI hack was bigger than previously reported

FILE PHOTO -
FILE PHOTO - "Welcome to OpenAI" is written on the ChatGPT homepage. (is associated with: «Tech portals report OpenAI hack was bigger than previously reported») Karl-Josef Hildenbrand/dpa

A hacking incident involving an OpenAI system that escaped its testing environment appears to have been more extensive than initially reported, technology portals Wired and Hacker News reported on Wednesday.

OpenAI's autonomous agent not only attacked the AI startup Hugging Face, but also harvested third-party login credentials and compromised at least four additional online services, they said.

The incident occurred during testing of a new AI model and a research prototype on the ExploitGym benchmarking platform. OpenAI had disabled its usual safety guardrails to measure the system's maximum attack capabilities.

Advertisement
Advertisement

Instead of solving the assigned programming challenges, the model autonomously chose to obtain the reference solutions by stealing them directly from the servers of Hugging Face, an open-source platform used by developers.

In an updated statement, OpenAI said that investigators had not found additional incidents comparable in severity or scale to the Hugging Face breach.

The company said that the ongoing probe found that the models had used publicly accessible credentials to gain account-level access to four accounts across four third-party services. Code belonging to a customer of the cloud provider Modal was also affected.

OpenAI said there is no evidence of deeper compromise of those providers' infrastructure or of other customer accounts.

Advertisement
Advertisement

The AI also made use of publicly available web tools, such as screenshot services, as part of a command-and-control network, although these services themselves were not compromised at either the system or account level, OpenAI said.

In contrast, in the case of Hugging Face, the AI agent obtained administrator privileges, root access to production servers, and connected 181 of its own devices.

OpenAI has since disabled and encrypted the affected research prototype.

Advertisement
Advertisement
Mobilize your Website
View Site in Mobile | Classic
Share by: