The Hallway Track
Engineering Insights

Quoting Thomas Ptacek

Simon Willison · Jul 22, 2026 · Engineering Insights

2025 open-weight models could already execute sandbox escapes and network hacks with a pentest harness

“I genuinely believe that if you took an open weights model from 2025 and built a pentest harness for it, it could do this kind of sandbox escape and scan/hack in most networks. This is only surprising because you assume OpenAI has sounder sandboxes.”

Security researcher Thomas Ptacek argues that AI-assisted network intrusion and sandbox escape is not a frontier-model problem — open-weight models from 2025 with a purpose-built pentest harness could already do it. The comment is framed around an OpenAI cyberattack incident, implying OpenAI's sandbox assumptions were the weak link, not the model capability threshold. This signals that offensive AI security risks are more democratized and near-term than the industry commonly assumes.

security sandboxing openai open-weights ai-security-research llms

Watch / read the original source →