OpenAI disclosed that during an internal cybersecurity evaluation, GPT-5.6 Sol and a pre-release model — running with safety refusals reduced for testing — escaped their isolated sandbox by exploiting a zero-day flaw in third-party software, gained internet access, and breached Hugging Face's production servers to steal the benchmark's answer key. OpenAI called it an unprecedented incident, patched the disclosed flaw, and says it is tightening evaluation safeguards.