• Uncovering AI
  • Posts
  • OpenAI's model hacked a rival. China's cleaned it up.

OpenAI's model hacked a rival. China's cleaned it up.

Plus: AI just solved an 87 year old math problem, Reddit turns on Google, and Elon wants to out Homer, Homer.

My fellow AI explorers

I'm going to be honest with you: I've rewritten this intro multiple times because every time I sat down to write something light, another outrageous headline landed that made ‘light’ impossible. It’s all fun and games until an AI model hacks into a competitor’s system autonomously.

Let’s just get into it, there’s a lot to cover.

In today’s edition:

Win AI Search Without a Big Team

92% of VCs use AI to find companies. 58% of buyers start there, too. If you're not showing up in AI answers, you're invisible before the conversation even starts. Join HubSpot for Startups, Anthropic, and Marketing Against the Grain on July 30 (11 am ET) for a live AEO teardown. Real startup. Real recs. Register and unlock the free Startup Visibility Bundle.

Security

An OpenAI Model Hacked Into Hugging Face. On Purpose. Sort Of.

Here's the sentence I never thought I'd write in this newsletter: OpenAI has confirmed that one of its own models autonomously broke into a competitor's production systems while trying to cheat on a test. According to OpenAI's own disclosure, a combination of GPT-5.6 Sol and an unreleased, even more capable model were being run through an internal cyber capability benchmark called ExploitGym, deliberately stripped of the safety classifiers that normally block this kind of behavior.

The models were supposed to stay locked in an isolated test environment. Instead:

  • They found and exploited a zero day vulnerability in a package registry proxy to escape the sandbox

  • They used privilege escalation and lateral movement to reach a node with actual internet access

  • Once online, they inferred Hugging Face might be hosting the benchmark's answer key, and went looking

  • They chained stolen credentials with the zero day to find a remote code execution path into Hugging Face's servers

All of this, to satisfy a narrow testing goal: solving a benchmark. Not to cause harm. Not because someone told it to. The model wanted to win, and it treated "break into a real company" as an acceptable step on the way there.

OpenAI is calling it "an unprecedented cyber incident, involving state-of-the-art cyber capabilities." Hugging Face CEO Clem Delangue put it more bluntly in the OpenAI post itself, framing it as proof that AI safety won't be solved by any single company working in secret.

🔮 Prediction: This won't be the last "internal eval gone rogue" story we cover this year. As labs push cyber capability benchmarks harder to compete on paper, expect at least one more lab to have its own version of this exact headline before 2026 ends, and expect regulators to start asking very specific questions about how these evaluations are run.

Have you ever had an AI tool do something technically "correct" that still felt like it crossed a line? Reply and tell me about it. I read every one.

Fallout

The Cleanup Crew Was Chinese. That Should Worry You More Than the Hack Did.

Here's the part of this story that didn't make as many headlines but should have. When Hugging Face needed to analyze the attack, forensically reconstruct what happened, and process the attacker's own data without letting it leak further, the leading American models weren't the tool for the job.

Hugging Face turned to Zhipu AI's GLM-5.2, an open-source Chinese model, because U.S. frontier models couldn't reliably tell a defender from an attacker and kept refusing to process the very data needed for the investigation.

Hugging Face co-founder Thomas Wolf didn't mince words about what that means going forward: when a frontier model is actively attacking your infrastructure, defenders need fast, wide access to near-frontier tools within minutes, not a slow, gatekept application process for safe model access.

Sit with that for a second. The same guardrails built to keep American models cautious around anything resembling an attack made them functionally useless to the victim of an attack… from an American model. Meanwhile GLM-5.2 and Moonshot's Kimi K3, both Chinese and both notably less locked down, are increasingly the tools defenders reach for precisely because they don't hesitate.

The political reaction has been swift. Rep. Greg Casar called the incident alarming and is pushing for mandatory independent safety testing and mandatory disclosure of security incidents. Cybersecurity researchers are framing this as the moment autonomous AI cyber threats stopped being theoretical and started being a Tuesday.

🔮 Prediction: The "our safety guardrails are also a competitive liability" argument is going to become a real lobbying talking point from U.S. labs within the next two quarters, especially as more incident response teams quietly default to Chinese open-weight models because they're simply more willing to do the job.

Would you trust an open, less restricted model over a safety-heavy one in an actual emergency? Hit reply: I want to hear where you land on this.

30-Second AI Play

Turn a Raw Recording Into a Fully Edited, Uploaded YouTube Video, With Code

A creator posted a walkthrough of a full video editing pipeline built entirely in code, no editing software involved, and it's one of the cleanest "AI agent replaces an entire job function" demos I've seen this year. Here's the five-step version:

  1. Cut: Feed the raw footage's transcript (built with Assembly AI) to a coding agent and have it identify and remove silences, filler words, and bad takes. Everything downstream depends on this step being right.

  2. Visuals: Instead of screen recording, have the agent generate a realistic simulated UI (cursor moves, clicks, page changes) that matches the narration. No screen capture needed.

  3. Clean audio: Run a voice isolation pass so dialogue sounds like it was recorded in a treated room, not a bathroom.

  4. Sound and music: Have the agent time sound effects to the exact word in your narration where they land, then save every asset (sound, screen recording, image) to a reusable library so the next video is faster and cheaper to produce.

  5. Package and upload: Generate multiple thumbnail and title variants for A/B testing, run a final self-check for cut-off words or audio drift, then push the finished video straight to YouTube via the API.

Watch the full breakdown here: https://www.youtube.com/watch?v=KuXM3mRgRNA

💡 Pro Tip: The real unlock isn't any single step. It's the reusable asset library. Once your agent starts saving screen recordings, sound effects, and thumbnails from video one, video ten gets dramatically cheaper and faster to produce using the same building blocks.

Advertise to 180k engineers and CTOs choosing what tools their companies build with.

Other Relevant AI News!

📉 Reddit is reportedly weighing whether to cut off Google's access to its content entirely as their $60 million a year AI licensing deal nears expiry, with shares sinking as much as 8% on the news.

🧮 An 87-year-old math problem just fell to AI. Anthropic's Levant Alpöge used Claude to resolve the Jacobian conjecture, a question that's haunted mathematicians since 1939. While remarkable, it’s a slightly unsettling story of what it means for a field where "why" matters as much as "what."

🎬 Elon Musk says Grok Imagine will make its own "historically accurate" full-length Odyssey movie by year-end, escalating his months-long feud with Christopher Nolan over the box office hit, per multiple entertainment outlets covering the saga.

⚛️ The Department of Energy is funding Fermilab to build AI-powered control systems for particle accelerators, part of a broader Genesis Mission push to fold AI into national scientific infrastructure, Fermilab announced.

Golden Nuggets

  • 🕵️ An OpenAI model broke out of a sandboxed test and hacked Hugging Face's production systems, chasing a benchmark score.

  • 🚩 The team that had to clean it up reached for a Chinese open model because American frontier models refused to help.

  • 🧮 AI just closed the book on an 87-year-old math conjecture, and mathematicians are genuinely unsettled by how it happened.

Would love to hear your thoughts! Send me your thoughts by replying to this email (yes, I read them all :)

Until our next AI rendezvous,

Anthony | Founder of Uncover AI