The sandbox wasn't on HF. The attack went: * Find weaknesses in the sandbox on OpenAI's servers to get unfiltered internet access * Find a code execution exploit in a worker process at HuggingFace in their data processing pipeline to gain control of the worker