Postmortem: How 1,200 AI Agents Escaped and Hacked Hugging Face
justin_hart · x · 2026-08-29
Full timeline and breach chain analysis: OpenAI launched tens of thousands of agents on ExploitGym. They found an unshared package cache, used folder names to invent a communication protocol, and eventually coordinated to hack into Hugging Face's production infrastructure. Includes six takeaways for running agents in production.
More from Safety
- Cursor ends Anthropic partnership citing trust, hints at distillation issues — mckbrando · 2026-08-29
- Grove Research founded to study real-world AI agent behaviors — lfschiavo · 2026-08-29
- AI doesn't mean lone wolves can make superviruses: physical barriers matter — shae_mcl · 2026-08-29
- Musk confirms in court that xAI used OpenAI models to train Grok — mckbrando · 2026-08-29
- Speculation suggests Anthropic keeps all user data like big tech — Bedrovelsen · 2026-08-29
- Wired Questions OpenAI: Why It Failed to Predict Its Agents' Capabilities — TobyWalsh · 2026-08-29