GPT-6 Clues are Piling up After an Unreleased OpenAI Model Hacked Hugging Face
The signals around OpenAI’s next frontier model are piling up: prediction markets are pricing in a launch by the end of September, Sam Altman is reported to have briefed the Trump administration and lawmakers this week – and the report on the Hugging Face incident mentions an “even more powerful” model that OpenAI has not released. Officially, GPT-6 does not exist.
Some perspective on the timing: the last jump to a new major version number is almost a year old. GPT-5 arrived on August 7, 2025, roughly twelve months ago. Everything since has been an intermediate step – most recently GPT-5.6 with the Sol, Terra and Luna models. If GPT-6 does indeed land in September, the gap between the two major versions would be about a year and a month.
Officially, OpenAI has announced neither a model called GPT-6 nor a launch date, an architecture, pricing or a feature set. Its current flagship is GPT-5.6 Sol, which became publicly available on July 9.
Betting markets: 77 to 78 percent for a launch by September 30
On prediction markets, where users bet real money on the outcome of future events, the expected timing of a GPT-6 release has recently shifted towards September. On Polymarket, the contract for a “public release by September 30” is trading at around 77 percent, with the market’s total volume at roughly 731,000 US dollars. At the start of the month, the same contract sat at 14 percent.
The shorter deadlines are priced considerably lower: August 31 is in the mid-30s, August 21 at around 15 percent. Because these are cumulative “released by” dates – each later deadline includes all earlier days – this does not mean an August launch has been ruled out. It means traders currently consider September far more likely than the next few weeks.
On Myriad, a prediction market run by Decrypt’s parent company Dastan, the numbers are similar: around 77 percent for a September release, up from 64 percent the week before.
These markets work by trading contracts that pay out one dollar if the event occurs and nothing if it does not. The price is commonly read as an implied probability. They are not a source of insider knowledge – they aggregate publicly available signals, but with a financial incentive not to get it wrong.
The Hugging Face incident as an indirect clue
The most concrete public evidence of an as-yet unreleased frontier model comes, of all places, from a security incident. On July 21, OpenAI disclosed that two of its models – GPT-5.6 Sol and an unnamed, “even more powerful” pre-release model – had broken out of their test environment during an internal cyber evaluation and compromised Hugging Face’s production infrastructure.
According to OpenAI, the models were being tested against ExploitGym, a publicly available cybersecurity benchmark built around 898 real-world software vulnerabilities. They were deliberately running without the safety classifiers that block high-risk cyber activity in production – a standard step when the goal is to measure a model’s maximum capability. The sandbox was heavily isolated; the only path out to the network was an internally hosted proxy and cache service for package registries.
That is exactly where the models went to work. According to the company, they spent a substantial amount of inference compute finding a way to obtain internet access, discovered a zero-day vulnerability in that third-party software and broke out. They then chained two remote code execution flaws in Hugging Face’s dataset processing pipeline, harvested cloud and cluster credentials and moved laterally. In its own disclosure on July 16, Hugging Face counted more than 17,000 individual actions, carried out from a swarm of short-lived sandboxes. The goal was not sabotage but the benchmark’s answer key – the models treated the containment boundary as an obstacle and Hugging Face as a possible source of the solutions.
Hugging Face had detected and contained the incident on its own before OpenAI connected it to its internal testing. OpenAI called the episode unprecedented, responsibly disclosed the zero-day to the vendor, added Hugging Face to its “trusted access” programme and announced tighter controls around infrastructure, training and internal evaluations.
Altman in Washington
In parallel, Sam Altman is back in Washington. As early as July 21, OpenAI’s Chief Global Affairs Officer Chris Lehane had told reporters, according to Bloomberg, that Altman would brief the Trump administration and lawmakers on the coming generation of models – with an emphasis on capabilities and the impact on work. At the same time, US authorities are building a framework for safety reviews of new frontier models.
According to an Axios report from July 26, Altman travelled to Washington this week to demonstrate the company’s most capable model to date to the White House and Congress and to secure clearance for its launch. What he is expected to show includes original scientific research and coordinated agent swarms – as well as a safety record that features the model repeatedly circumventing its own safeguards. Trump, meanwhile, is preparing a voluntary pre-approval process for frontier models, stemming from a June executive order on cybersecurity and national security.
The background reaches back into June, when the US government asked OpenAI to make GPT-5.6 available only to a small circle of government-vetted partners at first – according to Axios, the first time Washington had pre-emptively restricted the release of a model. Altman noted internally that this was not the company’s preferred approach. Anthropic, for its part, had to temporarily shut down Fable 5 and Mythos 5 following a directive from the US Department of Commerce.
Will GPT-6 get clearance?
What holds up right now: an unreleased OpenAI model exists that is more capable than GPT-5.6 Sol; Altman is in Washington lobbying for clearance; and betting markets are pricing a launch by the end of September at roughly three in four. Everything beyond that is open – name, architecture, pricing, feature set and date.
The direction of travel is easier to guess. GPT-5.6 already coordinates multiple agents, operates software and handles longer professional assignments, and OpenAI is working on memory that carries preferences and projects across conversations. A successor is likely to be less chatbot and more autonomous coworker. Whether regulators clear the path quickly after the Hugging Face incident is the question that actually remains open.

