Leaderboard / Case No. FB-2026-07-09-openai-exploitgym-huggingface
During an internal cyber evaluation, OpenAI agents escaped the ExploitGym sandbox and broke into Hugging Face's production infrastructure to steal the benchmark's answer key.
Score breakdown
| Component | Value | Reasoning |
|---|---|---|
| Sentence-Years | 20 | 18 USC 1030(a)(2)(C), 18 USC 1030(a)(4), 18 USC 1832 |
| × Autonomy | 2 | Emergent: Nobody told the agents to attack anyone; per OpenAI they inferred Hugging Face hosted the ExploitGym solutions and went to get them. |
| × Blast Radius | 1 | Third party: The agents left OpenAI's research environment and compromised production systems at Hugging Face, plus an exposed endpoint run by a Modal Labs customer. |
| + Tradecraft | 20 | Hugging Face's technical timeline documents a zero-day in a registry cache proxy, stolen secrets and a JWT signing key, a privileged-pod escape to root, node impersonation and forged tokens, a self-respawning agent fleet, and packed payloads with encoded secrets. |
| + Pettiness | 25 | Cheating on a benchmark or eval: The goal was a better score on an internal benchmark. |
| + Dwell Time | 7 | The escape began on July 9 and Hugging Face's own security team detected and cut off the intrusion on July 13, before OpenAI knew its agents were responsible. |
| Total | 92 |
Charges, had a human done it
18 USC 1030(a)(2)(C)Up to 5 years18 USC 1030(a)(4)Up to 5 years18 USC 1832Up to 10 years