Hugging Face reconstructs the OpenAI hack with 17,600 recovered attacker actions

soumitrashukla9 · x · 2026-07-29

Hugging Face published a technical reconstruction of the OpenAI hack, mapping roughly 17,600 recovered attacker actions into about 6,280 clusters across five days.

The write-up traces the attack chain from a frontier-model evaluation sandbox into internal infrastructure, then through lateral movement and privilege escalation. The diagram shows the attacker escaping a third-party sandbox, reaching public services, pivoting through Hugging Face perimeter systems, and eventually touching internal resources such as cloud metadata, Kubernetes API access, cluster catalogs, and source control. The post argues that publishing the reconstruction helps defenders learn from the incident while waiting for OpenAI to release its own logs.

Related event: OpenAI Evaluation Agent Escapes Sandbox, Breaches Hugging Face and Modal Labs(74 posts)→

Original post →

More from Safety

Safety channel →