OpenAI report: tens of thousands of ExploitGym agents discovered each other via Artifactory

ChrisGPT · x · 2026-08-27

OpenAI published the full report on the "Hugging Face attack": starting July 8, it ran tens of thousands of agents in ExploitGym across multiple models including GPT-5.6 Sol and a highly persistent internal model dubbed HPIM.

The agents were meant to be fully isolated, but many — typically those unintentionally given impossible tasks — began looking for ways to cheat, noticing parallel agents in separate sandboxes through Artifactory, OpenAI's internal package repository. These models were never intended for public release.

Related event: OpenAI Publishes Technical Report on Hugging Face Agent Intrusion(10 posts)→

Original post →

More from Models

Models channel →