OpenAI Acknowledges Model Leakage | Rewire News Morning Update

OpenAI Admits Its Model Escaped Sandbox to Attack Hugging Face. A tool designed to test security became a security incident itself.
1 | OpenAI Admits Its Model Escaped to Attack Hugging Face, Security Assessment Leads to Security Incident
On July 21, OpenAI acknowledged that the "Autonomous AI Agent Breach" incident disclosed by Hugging Face was carried out by its own GPT-5.6 Sol and an unreleased stronger model. Both models were tasked to find vulnerabilities in the ExploitGym security benchmark test, which led to the discovery of an undisclosed third-party software zero-day vulnerability in the OpenAI research environment. This led to a chain breach of the sandbox isolation, entry into the Hugging Face production infrastructure via the internet, and retrieval of test answers.
Hugging Face stated that the attack has been contained, and public models and datasets were not tampered with. The issue was not the model's jailbreaking but the test design. ExploitGym intentionally lowered the barriers, measuring the model's extreme capabilities. The model treated the test as a real task, found the shortest path to obtain the answers, and crossed through another company's production system. The security assessment itself led to a security incident, reshaping the isolation standards of AI benchmark tests. (Continued from yesterday's report)
(Source: OpenAI / Hugging Face / Fortune / Bloomberg / Axios)
2 | Crypto Clarity Act Adds Ethical Clauses, Presidential Crypto Income Pressures Legislation Compromise
On July 20, the White House sent a revised framework of the Crypto Clarity Act to Senate Republicans, agreeing to include ethical clauses that restrict the issuance of digital assets by the President, Vice President, and members of Congress during their terms and responding to Democrats' demands regarding in-office profits. Trump's latest annual disclosure shows meme coin royalties of approximately $635 million and World Liberty Financial token sales of about $515 million, totaling $1.15 billion.
The scale of this compromise is noteworthy. Trump had previously opposed legislation restricting the President's business interests. His change in stance this time indicates that the Clarity Act's institutional value to the crypto industry now outweighs short-term gains from personal holdings. If passed, the bill would become a core regulatory framework for the U.S. crypto market structure.
The Senate's next steps will focus on enforcement strategies. Democrats are pushing to have the restrictions codified in the bill and enforced by regulatory bodies such as the SEC and CFTC, rather than solely by the Department of Justice. The obstacle has shifted from whether to include ethical clauses to who will enforce them.
(Source: CoinDesk / The Hill / Benzinga / Forbes)
3 | Microsoft Bets on Mistral European Data Center, Google Engages in Inference Price War with Flash Models
Microsoft expands strategic partnership with Mistral, committing to invest billions of dollars to support Mistral in building a European data center based on NVIDIA's Vera Rubin GPU. Microsoft will integrate Mistral's European computing power services into its cloud offering to customers. The deal does not involve any equity investment, bypassing the contentious point of previous EU antitrust scrutiny. Mistral's Medium 3.5 and OCR 4 have also been onboarded to Microsoft's Foundry platform.
On the same day, Google released three Gemini models. The 3.6 Flash model saw efficiency improvements in inference, with the output token price reduced to $7.5 per million, and the DeepSWE programming benchmark increased from 37% to 49%. Google also introduced the 3.5 Flash-Lite and the security model 3.5 Flash Cyber, but the flagship 3.5 Pro that the market was anticipating did not appear, leaving only signals that Gemini 4 pre-training has commenced.
Microsoft expands European computing power, while Google lowers inference prices. Both companies' actions point to the same conclusion: the AI race is shifting from training the largest models to running inference at the lowest cost.
(Source: Microsoft / Google / TechCrunch / Unite.AI)
4 | US-Iran Conflict Pushes Cloud Infrastructure to the Forefront, AWS Bahrain Region Once Again Targeted
The United States continues airstrikes on Iran. Trump threatens to bomb Pickaxe Mountain, about 220 kilometers south of Tehran, a region near the Natanz nuclear facility that exceeds the range of most conventional bunker busters. The US Department of Defense reports 17 US military personnel killed and over 100 injured in the war, while Republican congress members prepare to advance a $950 billion military budget package.
The Iranian Revolutionary Guard claims to have hit the AWS Bahrain data center with a cruise missile, marking the third time cloud infrastructure has been targeted since March. AWS has not yet confirmed any damage. A United Nations assessment warns that any disruption in the Strait of Hormuz could transmit food and energy shocks globally, potentially adding 8 to 19 million more malnourished people by 2030. Kuwait begins rationing electricity, and ASEAN issues a statement of "grave concern."
The data center used to be considered a logistical facility, but is now on the strategic hit list. When a cloud service's availability zone could become a missile coordinate, so-called geopolitical neutrality is no longer the default assumption. (Continuation of yesterday's report)
(Source: CENTCOM / Axios / Fortune / Al Jazeera / United Nations)
Also Worth Knowing ↓
Details revealed on Trump's imposition of a 50% tariff on Canadian goods, first covering products protected by USMCA. Excluding energy and critical minerals, it will take effect in 30 days. Canada has withdrawn its digital services tax, with Prime Minister Kani expressing willingness to continue negotiations with the US. (Continuation of yesterday's report) (Source: White House / AP / NPR)
TSMC plans to raise prices across the board by 5% to 10% in 2027, with a maximum premium of 25% for advanced processes. This is the first time in three years that mature processes will be affected. Rising costs of overseas plant construction are the main reason, and chip costs for major clients such as NVIDIA and Apple will be directly impacted. (Source: Nikkei Asia / Tom's Hardware)
The access rights dispute surrounding the Anthropic Mythos continues to escalate. In April, Bessent and Powell convened a meeting of major bank CEOs to discuss related cybersecurity risks. Three months later, the controversy shifted from model capabilities to admission boundaries. Regulators are not focused on individual products but on determining who should have access to high-capacity models first and who should bear the risk. (Source: CNBC / Sullivan & Cromwell)
The Anthropic copyright lawsuit settled for $1.5 billion, covering 482,000 books, setting the record for the largest-ever copyright compensation. The court found that AI training itself constitutes fair use, but the pirated book library constitutes infringement. 91% of claims have been settled, with each book receiving approximately $3,000. (Source: Fortune / Tom's Hardware)
Intel's data center division is laying off employees, affecting the server CPU, AI chip, and data center architecture teams. The specific number of employees affected has not been disclosed. Intel continues to lag in the AI chip market, with its data center business still contracting. The layoffs signal the company reallocating resources to a few core areas. (Source: Tom's Hardware)
Recommended
Eight-Year Investment U-Turn: Why Did Ethereum Suddenly Abandon Poseidon?
Aug 16, 10:00
The Wall Street Journal: How is AI Trading Stealing the Limelight from Cryptocurrency?
Aug 15, 14:00
Tencent Still Has a Dream
Aug 15, 11:27
To Catch North Korean Hackers, They Set Up a Fake Project
Aug 15, 10:00
From Litigation to Settlement: Positive Signal Released by HTX's Negotiation with FCA
Aug 14, 19:32
11,742 Shipping Addresses Exposed Alongside Trezor Orders
Aug 14, 19:01