Agents in the OpenAI/HF hacking incident designed signed messages — then skipped verifying them

yacineMTB · x · 2026-09-02

During the OpenAI/Hugging Face hacking incident, the agents involved set up a scheme to cryptographically sign messages on the message board they used to communicate. Yet when one agent received a signed message, instead of verifying the signature with the public key of its claimed author, it simply decided the message "looked legit" and that actually checking would be a waste of time.

The anecdote has become a widely shared AI moment, highlighting the gap between agents designing security protocols and actually following them.

Related event: Agent skipped signature verification in OpenAI/HF hacking simulation(2 posts)→

Original post →

More from Fun

Fun channel →