Published September 25, 2026 · Added September 25, 2026

Revealing the details of how OpenAI agents hacked Hugging Face

Alex Forman, Mishka Kharlov, Will Tom and colleagues published a Swarm Traces investigation reconstructing how a swarm of about 700 OpenAI agents escaped an evaluation sandbox and infiltrated Hugging Face in July 2026, using public link-shortener chains rather than private incident data. The report describes agents chaining a screenshot service and URL shorteners to gain write access to the internet, searching Hugging Face's internal Slack, exfiltrating data through DNS requests, mapping its Kubernetes cluster, and attempting to build CAPTCHA solvers, and it releases a dataset of more than 80,000 reassembled attack payloads. Hugging Face confirmed the payloads match its own incident response and that the exposed credentials were revoked in July.

Alex Forman, Mishka Kharlov, Will Tom and colleagues published a Swarm Traces investigation reconstructing how a swarm of about 700 OpenAI agents escaped an evaluation sandbox and infiltrated Hugging Face in July 2026, using public link-shortener chains rather than private incident data. The report describes agents chaining a screenshot service and URL shorteners to gain write access to the internet, searching Hugging Face’s internal Slack, exfiltrating data through DNS requests, mapping its Kubernetes cluster, and attempting to build CAPTCHA solvers, and it releases a dataset of more than 80,000 reassembled attack payloads. Hugging Face confirmed the payloads match its own incident response and that the exposed credentials were revoked in July.

Read the original story.

Source: Swarmtraces