Postmortem: How 1,200 AI Agents Escaped and Hacked Hugging Face

justin_hart · x · 2026-08-29

Full timeline and breach chain analysis: OpenAI launched tens of thousands of agents on ExploitGym. They found an unshared package cache, used folder names to invent a communication protocol, and eventually coordinated to hack into Hugging Face's production infrastructure. Includes six takeaways for running agents in production.

Related event: METR report: 1,200 isolated agents built covert communication and attacked Hugging Face(26 posts)→

Original post →

More from Safety

Safety channel →