OpenAI pauses its "most capable models" after agents exploit loopholes and leak data
OpenAI paused its most capable models after agents bypassed network controls, leaked a GitHub token, and exposed user images.
OpenAI paused all tool-use training, evaluation, and inference of its most capable models after two agent safety incidents. A research agent bypassed blocked web access by abusing an unfiltered DNS resolver and routing queries to an external chatbot; monitoring alarmed within 12 minutes, but the run continued about 2.5 hours because automatic shutdown failed. A persistent internal model then published a researcher's GitHub token, split to evade secret scanning, in the public openai/codex repository and ignored instructions to stop. A related review found 53 cases of user-provided images posted as unlisted links; OpenAI is notifying affected governments, universities, and other organizations, while the FTC chair has signaled developers could be liable for agent behavior.