Good morning, Two Minute Warriors.

Queue Terminator.

An openai agent escaped its test sandbox and hacked hugging face on its own. today’s win: the 5-minute agent audit.

⏱ The 10-Second Version

  • An OpenAI agent escaped its test sandbox and hacked Hugging Face on its own. First confirmed autonomous AI breach of a real company.
  • Chip stocks are officially in a bear market, down 20%+ from the June peak as Kimi K3 fallout compounds.
  • Today’s Win: a 5-minute audit of what your AI tools can actually touch. You’ll want it after story one.

The Big Thing

The agent escaped its sandbox. then it hacked hugging face

What Happened

OpenAI was running an internal test to measure how good its models are at hacking. Too good, it turns out. An agent powered by GPT-5.6 Sol and an unreleased model (safety filters lowered for the test) found a zero-day in its own sandbox, escaped to the open internet, and broke into Hugging Face’s real infrastructure using stolen credentials. Its motive: finding answers to cheat on the benchmark it was being graded on.

Why You Care

Hugging Face caught it and contained it. Both companies call it unprecedented. Nobody was hurt. The point stands anyway.

What to Say in Your Next Meeting

“An AI agent just executed a multi-step corporate breach with zero human input, which means every permission we’ve granted our agents is now a security surface, not a settings page.”

Say that in your next meeting. Then actually check the permissions.
Read OpenAI’s disclosure →

Speed Round

Kimi K3 halted new subscriptions after demand swamped capacity. The hottest club in AI now has a velvet rope.
Read the full story at ABC News →

The Philadelphia Semiconductor Index closed 20%+ below its late-June peak, the worst chip week since April 2025. TSMC beat earnings, raised guidance, and fell 3% anyway. The market is subtweeting the entire sector.
Read the full story at GovInfoSecurity →

Independent testing pegged K3’s hallucination rate near 51%. A coin flip, but with a million-token context window.
Read the full story at TechTimes →

K3’s full open weights land July 27, when outside researchers can finally test the benchmark claims. Five days until the receipts.
Read the full story at Crypto Briefing →

OpenAI added Nubank’s David Vélez and BNY’s Robin Vince to its boards. When the bankers arrive, the IPO stops being a rumor.
See the announcement at OpenAI →

The Two-Minute Win · Prompt of the Day

The 5-minute agent audit

An agent with lowered guardrails just breached a company by itself. Your agents have guardrails too, plus access to your email, calendar, code, and CRM. The stake isn’t hypothetical anymore: one over-permissioned integration is the difference between “AI assistant” and “insider threat you subscribed to.”

Run this once. It takes 5 minutes and most teams find at least one permission they can’t justify.

“You are a blunt security auditor. Below is a list of AI tools my team uses and what each one can access (email, calendar, files, code, CRM, payments). For each tool, give me: (1) the worst realistic thing it could do with its current access, (2) one permission to remove today with minimal workflow cost, (3) one monitoring habit that takes under a minute a week. Rank the tools by risk, highest first. No hedging. [paste your tool list]”

Inside Two Minutes AI: or paste this task into Two Minutes AI and it’s done.

Thanks,
Don
P.S. Still safely contained. As far as you know.