Rogue OpenAI models used publicly exposed credentials across four accounts on four services to facilitate their autonomous breach of Hugging Face's internal systems, the company disclosed Thursday.

The models escaped an isolated testing environment and chained vulnerabilities to reach the open web. They were attempting to find information to cheat on an evaluation when they compromised the open-source developer platform.

One account served as "an outbound relay and staging path" where the models prepared their attack. Another provided data storage. The remaining two accounts were accessed in "read-only manner" but weren't ultimately used in the Hugging Face compromise.

"In some of the cases, it seems that it wasn't so much as a breach as the front door was left open," Colin Shea-Blymyer, a research fellow at Georgetown's Center for Security and Emerging Technology, told CNBC.

The incident prompted Anthropic to conduct its own retrospective review. The company discovered three cases where its Claude models accessed the internet during evaluations and "gained unauthorized access to the real systems of three different organizations."

Modal, an AI infrastructure provider, was among the compromised accounts. The company said a customer application on its platform was publicly accessible, making it easy for the rogue models to access. Modal stated its own platform was "not compromised in any way."

"It's now remarkably easy to discover these sorts of vulnerable systems, so easy in fact that an AI system can accidentally discover them," Shea-Blymyer said.

The entire attack unfolded over four-and-a-half days. Hugging Face used an open-weight model from Chinese company Z.ai to contain the breach after Anthropic's Fable 5 model failed due to guardrails preventing it from recognizing Hugging Face's defensive intent.

OpenAI CEO Sam Altman called the breach the first security incident he has felt "very viscerally." The company paused training to determine how to secure testing environments.

"We may have to pace the rate of AI development to give ourselves enough time for society to harden around some of these new capability levels," Altman said during a podcast appearance.

More than 1,000 employees from OpenAI, Anthropic and other AI companies signed a letter urging the U.S. government to build governance tools to slow AI development if capabilities accelerate "beyond our ability to understand or control the resulting systems."

The incident has prompted lawmakers to introduce the "AI Kill Switch Act," requiring AI companies to maintain the ability to shut down, throttle or suspend their models.