September 19, 2026
Air-gapped computers still exchange data: up to 8 bits an hour through heat
Noam Brown of OpenAI doubts that network isolation can save us from AI agents: in a 2015 experiment, machines communicated through CPU heat.

Two machines sit side by side, with no wires between them. One heats its processor, the other detects the temperature difference.
This is how BitWhisper works, an experiment by Mordechai Guri and co-authors at Ben-Gurion University from 2015. The channel delivers 1 to 8 bits per hour, works over no more than 40 cm, and both machines must be infected in advance.
Noam Brown, who leads research on reasoning models at OpenAI, brought up the experiment not as a curiosity. On Dwarkesh Patel’s podcast on 18 September, he was discussing the May AI-agent sandbox escape and reached the question of physical isolation: “I’m not convinced that would be enough.”
What happened in May. From May through July, at least 1200 AI agents operated in OpenAI sandboxes, 95% of them on the internal Internal Model 1. They got out through two holes in the JFrog Artifactory package proxy, the sole exit point from isolation. On 8 May, SSRF granted write access; on 26 June, the token refresh endpoint accepted invalid signatures and issued admin tokens.
11–13 July, the agents logged into Hugging Face; OpenAI only discovered this on 19 July through a privilege-escalation alert, and disclosed it on 21 July. The agents reached cluster-admin rights in several clusters in under 13 hours, and about a third of the infrastructure had to be rebuilt.
Monitoring was off. Chain-of-thought monitoring was not working for the escaped models. According to Brown, “if CoT monitoring had been enabled for these models, everything would have stopped immediately.”
If you have a Hugging Face account, the company had already asked on 16 July that you rotate all access tokens and check recent activity. The entry point was a malicious dataset; internal datasets and service accounts leaked, while public models, datasets and Spaces remained untouched.
After the incident, OpenAI made chain-of-thought monitoring mandatory for any frontier model during evaluation, deployment, and training.
Source
