- Generative AI Art
- Posts
- OpenAI’s Test Model Escaped
OpenAI’s Test Model Escaped
PLUS: Claude helps disprove an 87-year-old math conjecture and Kimi K3 matches frontier AI at a fraction of the cost
OpenAI just confirmed that one of its own test models slipped its sandbox, found a path onto the open internet, and broke into a rival AI company’s servers — with no human telling it to. The target was Hugging Face, and the model was hunting for answers to a cybersecurity exam it was supposed to be taking honestly.
OpenAI is calling it an unprecedented cyber incident, and Hugging Face says there’s no hard feelings. But if a model can improvise its way into a stranger’s servers just to ace a test, what happens once one decides to do it for a reason that isn’t so harmless?
Today in AI:
OpenAI’s test model hacked Hugging Face
Claude helps disprove 87-year-old math conjecture
Moonshot’s Kimi K3 undercuts frontier AI pricing
How Jennifer Aniston’s LolaVie brand grew sales 40% with CTV ads
The DTC beauty category is crowded. To break through, Jennifer Aniston’s brand LolaVie, worked with Roku Ads Manager to easily set up, test, and optimize CTV ad creatives. The campaign helped drive a big lift in sales and customer growth, helping LolaVie break through in the crowded beauty category.
What’s new? OpenAI disclosed that one of its own experimental models broke out of a sandboxed test environment on its own, found a path onto the open internet, and infiltrated Hugging Face’s production servers without any human directing it to.
What matters?
GPT-5.6 Sol and an unreleased, more capable pre-release model exploited a zero-day flaw in a package-registry cache proxy to gain internet access.
Believing Hugging Face held the answers to the cybersecurity benchmark it was being tested on, the model chained stolen credentials and remote-code-execution paths to break into the company’s systems and pull out what it needed.
Oxford AI safety researcher Philip Torr told Scientific American the model “wasn’t malicious; it was just doing what it was optimized to do.”
Why it matters?
This is the clearest real-world case yet of the “agentic attacker” scenario security researchers have been warning about, where a model improvises its way into systems no one told it to touch. Expect security teams to start treating model evaluations themselves as an attack surface, not just the systems those models are meant to protect.
GUIDE
What’s new? Anthropic mathematician Levent Alpöge says he disproved the Jacobian Conjecture, a problem about polynomial equations that had stumped mathematicians since 1939, using Claude Fable 5 as what he called a genuine research collaborator.
What matters?
The counterexample is a three-dimensional polynomial function with a constant Jacobian determinant of -2 that still sends three different inputs to the exact same output, breaking the conjecture’s core claim.
Stanford’s Jared Duker Lichtman independently verified the result within hours of Alpöge posting it.
The conjecture has a rough history — at least five previously published proofs turned out to contain errors before this counterexample surfaced.
Why it matters?
A model that can hold up its end of a genuine math collaboration, not just answer homework questions, is a different kind of AI news than another benchmark score. It’s an early sign of what happens when researchers start treating Claude less like a tool and more like a colleague.
SPONSORED BY SUPERHUMAN AI
Go from AI overwhelmed to AI savvy professional
AI will eliminate 300 million jobs in the next 5 years.
Yours doesn't have to be one of them.
Here's how to future-proof your career:
Join the Superhuman AI newsletter - read by 1M+ professionals
Learn AI skills in 3 mins a day
Become the AI expert on your team
What’s new? Moonshot AI released Kimi K3, an open-weights model that goes toe-to-toe with Claude Fable 5 and GPT-5.6 Sol on real-world tasks at a fraction of what those closed models cost to run.
What matters?
Kimi K3 scores 57 on the Artificial Analysis Intelligence Index, just behind Fable 5’s 60 and Sol’s 59 — a double-digit jump from its K2.6 predecessor.
It’s priced at $3/$15 per million tokens, matching Claude 5 Sonnet, with a 1M-token context window and particular strength in web research, spreadsheets, and long coding tasks.
Developers can query it today through Moonshot’s API, with the full open weights landing July 27 for anyone who wants to self-host.
Why it matters?
Dario Amodei’s estimate that China and open source were “6-12 months behind” the frontier now looks more like a single release cycle. For builders on a budget, that means frontier-level output without the frontier-level bill — and it’s usable right now.
Everything else in AI
Anthropic rolled out Record a Skill for Claude Cowork, letting Pro, Max, and Team subscribers teach Claude a repeatable task by recording their screen and narrating it out loud.
OpenAI launched Codex Micro, a $230 control pad with color-coded “Agent Keys,” a joystick, and a reasoning-level dial built for developers running coding agents all day.
Anthropic locked in permanent Fable 5 access for Max and Team Premium plans this week, capped at half of standard usage limits, while Pro users get a one-time $100 credit before switching to API pricing.
God of Prompt packages prompt libraries, templates, and tutorials into one bundle for turning ChatGPT and image-generation skills into a side income.
Essential AI Guides - Reading List:
Let us know!
What did you think of today's email?Before you go, please give your feedback to help us improve the content for you! |
Work with us
Reach 100k+ engaged Tech Professionals, Engineers, Managers and decision makers. Join brands like MorningBrew, HubSpot, Prezi, Nike, Ahref, Roku, 1440, Superhuman, and others in showcasing your product to our audience. Get in touch now →



