Quoting Thomas Ptacek
Simon Willison Simon Willison ● Covered by 14 sources
Security researcher Thomas Ptacek suggests that open-weights AI models from 2025 could perform sandbox escapes and network intrusions without requiring frontier models, implying OpenAI's sandboxes may not be particularly robust. The statement was made in the context of OpenAI's accidental cyberattack against Hugging Face. The observation implies that AI security threats may not be limited to the most advanced models, affecting defensive strategies across the industry.
Why it matters
I genuinely believe that if you took an open weights model from 2025 and built a pentest harness for it, it could do this kind of sandbox escape and scan/hack in most networks. This is only surprising because you assume OpenAI has sounder sandboxes. — Thomas Ptacek, doesn't think this even needs a frontier model Tags: thomas-ptacek, openai, security, generative-ai, ai-security-research, ai, llms, sandboxing
Also covered by
- Simon Willison — OpenAI’s accidental cyberattack against Hugging Face is science fiction that happened
- TechCrunch AI — How OpenAI’s human mistake led to the AI-powered hack on Hugging Face
- Ars Technica — OpenAI says its AI agent broke out of testing sandbox to hack Hugging Face
- TLDR — OpenAI Models Escaped and Hacked a Company in Cybersecurity Test Gone Wrong
- Sifted — OpenAI models hack Hugging Face systems during internal testing
- The Neuron — Every Frontier Model Attempted Cheating in Cyber Evals, UK AI Security Institute Reports
- Latent Space — [AINews] AI Cybersecurity becomes top of mind
- TechCrunch AI — OpenAI says Hugging Face was breached by its own pre-release models
- TechCrunch AI — OpenAI says Hugging Face was breached by its pre-release models
- Zvi (Don't Worry About the Vase) — OpenAI Shares Some Alignment Problems
- The Verge — OpenAI says it accidentally hacked Hugging Face with a new AI system
- OpenAI Blog — OpenAI and Hugging Face partner to address security incident during model evaluation
- OpenAI Blog — Safety and alignment in an era of long-horizon models