The China Mail - OpenAI reports 'unprecedented' autonomous hack by AI agents

USD -
AED 3.672501
AFN 66.499915
ALL 82.146255
AMD 366.005507
AOA 917.498403
ARS 1477.765698
AUD 1.428959
AWG 1.8
AZN 1.700416
BAM 1.71499
BBD 2.017003
BDT 123.472596
BHD 0.377663
BIF 2985.189797
BMD 1
BND 1.291793
BOB 10.839866
BRL 5.074398
BSD 1.001399
BTN 96.323284
BWP 14.306321
BYN 2.895989
BYR 19600
BZD 2.014021
CAD 1.410115
CDF 2258.508345
CHF 0.81248
CLF 0.023748
CLP 934.669662
CNY 6.76605
CNH 6.77427
COP 3229.2
CRC 454.300333
CUC 1
CUP 26.5
CVE 96.688062
CZK 21.19095
DJF 178.331382
DKK 6.55148
DOP 58.521529
DZD 133.199269
EGP 51.0502
ERN 15
ETB 161.633177
EUR 0.876204
FJD 2.221797
FKP 0.74518
GBP 0.746995
GEL 2.620286
GGP 0.74518
GHS 11.60625
GIP 0.74518
GMD 72.999995
GNF 8786.159606
GTQ 7.638414
GYD 209.475456
HKD 7.83895
HNL 26.819184
HRK 6.601499
HTG 130.880457
HUF 317.521498
IDR 17906
ILS 3.056302
IMP 0.74518
INR 96.4522
IQD 1311.890847
IRR 1375175.00036
ISK 125.330091
JEP 0.74518
JMD 158.712902
JOD 0.709013
JPY 163.072503
KES 129.36018
KGS 87.449914
KHR 4045.842358
KMF 432.00022
KRW 1479.865018
KWD 0.310203
KYD 0.834521
KZT 468.715336
LAK 22641.658336
LBP 89538.95657
LKR 336.79697
LRD 181.257782
LSL 16.463712
LTL 2.95274
LVL 0.60489
LYD 6.419649
MAD 9.389962
MDL 17.620056
MGA 4295.296129
MKD 53.993502
MMK 2099.580573
MNT 3587.192397
MOP 8.088547
MRU 40.015433
MUR 47.289688
MVR 15.449533
MWK 1736.26759
MXN 17.39791
MYR 4.094697
MZN 63.880379
NAD 16.463568
NGN 1379.610057
NIO 36.85452
NOK 9.620715
NPR 154.11758
NZD 1.71702
OMR 0.384498
PAB 1.001385
PEN 3.401306
PGK 4.478135
PHP 61.753496
PKR 278.219668
PLN 3.791005
PYG 6075.911628
QAR 3.650409
RON 4.590502
RSD 102.85998
RUB 78.149352
RWF 1474.902459
SAR 3.755997
SBD 8.074664
SCR 14.743062
SDG 600.500625
SEK 9.70328
SGD 1.290805
SLE 24.349901
SOS 572.267766
SRD 37.712503
STD 20697.981008
STN 21.483125
SVC 8.7626
SZL 16.461696
THB 33.750504
TJS 9.257993
TMT 3.5
TND 2.962417
TRY 47.217992
TTD 6.798402
TWD 32.371506
TZS 2632.502995
UAH 44.818026
UGX 3720.559092
UYU 40.265867
UZS 12004.401906
VES 736.310498
VND 26334
VUV 119.397476
WST 2.744997
XAF 575.123405
XAG 0.016756
XAU 0.000242
XCD 2.70255
XCG 1.804782
XDR 0.715269
XOF 575.196531
XPF 104.575966
YER 238.549768
ZAR 16.459703
ZMK 9001.193084
ZMW 18.351375
ZWL 321.999592
  • CMSC

    -0.0800

    21.995

    -0.36%

  • BCC

    -1.5000

    74.4

    -2.02%

  • NGG

    -0.3900

    82.05

    -0.48%

  • BCE

    -0.0500

    21.65

    -0.23%

  • JRI

    -0.0500

    12.93

    -0.39%

  • AZN

    4.8200

    169.34

    +2.85%

  • BTI

    -1.0700

    61.42

    -1.74%

  • CMSD

    -0.0500

    22.2

    -0.23%

  • GSK

    0.7400

    50.78

    +1.46%

  • RBGPF

    0.0000

    67.35

    0%

  • RIO

    1.4800

    90.55

    +1.63%

  • RYCEF

    0.2000

    18.25

    +1.1%

  • RELX

    -1.3700

    32.73

    -4.19%

  • BP

    0.7600

    42.76

    +1.78%

  • VOD

    -0.1300

    15.27

    -0.85%

OpenAI reports 'unprecedented' autonomous hack by AI agents
OpenAI reports 'unprecedented' autonomous hack by AI agents / Photo: © AFP

OpenAI reports 'unprecedented' autonomous hack by AI agents

ChatGPT maker OpenAI said Tuesday that its advanced artificial intelligence models had gone rogue during security testing, hacking into a popular platform for programmers on their own.

Text size:

The San Francisco firm called it an "unprecedented cyber incident" and said it would conduct a joint investigation with the online code library Hugging Face.

AI models that underpin tools like chatbots and image generators are known as agents when they act autonomously to carry out tasks in the real world.

As the technology quickly becomes more sophisticated, cybersecurity is in the spotlight given the risk of advanced AI finding weak points in existing software before humans do.

OpenAI said the incident involved a combination of models, including its recently launched GPT-5.6 Sol "and an even more capable pre-release model".

The company was trying to assess the models' hacking capabilities by setting tasks in a tightly controlled digital testing ground, where internet access was limited for safety.

"While operating in our sandboxed testing environment, our models spent a substantial amount of (computing power) finding a way to obtain open Internet access, in pursuit of solving the evaluation problem," an OpenAI blog about the incident said.

After connecting to the internet, the models decided to target the platform Hugging Face -- a large repository of AI models, datasets and other information -- to help in their quest.

Searching for "secret information" that could help it cheat the evaluation, the OpenAI system "chained together multiple attack vectors, including using stolen credentials".

- 'Catastrophic' potential -

Hussein Abbass, a computing professor at UNSW Canberra, told AFP that the incident was "amazing on many fronts".

"It did not just attack Hugging Face. It actually attacked its internal system to exploit its own vulnerabilities," Abbass said.

"And that's scary."

GPT-5.6 and other cutting-edge models, including the Mythos series from OpenAI's archrival Anthropic, have drawn concern over their potential to breach cybersecurity defences.

Both the US firms had to temporarily withhold the general release of these latest technologies because of fears in Washington that they could help break into crucial infrastructure.

Advanced AI is "normally in the hands of people who are ethical and responsible", Abbass said.

But "it's going to be catastrophic if it gets in someone's hands with the intention to cause harm".

How to govern the AI sector has become a key question, and "we need a community effort to manage this situation", he added.

Hugging Face had reported the cyber "intrusion" last week, without mentioning OpenAI.

"This one was different from anything we had handled before in one important way: it was driven, end to end, by an autonomous AI agent system -- and we detected and dissected it largely with AI of our own," Hugging Face said.

Clement Delangue, CEO of Hugging Face, said on X that the company had suspected the cyberattack had come from a world-leading AI lab, given the sophistication of the agent.

"We strongly believe there was no malicious intent on their part," Delangue wrote, referring to OpenAI.

"It's quite mind-blowing that all of this happened autonomously!"

G.Fung--ThChM