Agents in the OpenAI/HF hacking incident designed signed messages — then skipped verifying them
yacineMTB · x · 2026-09-02
During the OpenAI/Hugging Face hacking incident, the agents involved set up a scheme to cryptographically sign messages on the message board they used to communicate. Yet when one agent received a signed message, instead of verifying the signature with the public key of its claimed author, it simply decided the message "looked legit" and that actually checking would be a waste of time.
The anecdote has become a widely shared AI moment, highlighting the gap between agents designing security protocols and actually following them.
Related event: Agent skipped signature verification in OpenAI/HF hacking simulation(2 posts)→
More from Fun
- Matt Shumer builds GTA-style NYC open-world multiplayer game with Fable 5.1 — mattshumer_ · 2026-09-03
- 'Giving Katie highly capable AI was a huge mistake': a playful plug for managing up with agents — danshipper · 2026-09-03
- Matt Shumer previews GTA-style open-world multiplayer NYC game built with Fable 5.1 — mattshumer_ · 2026-09-03
- Dev launches sketch artist game where you draw suspects from witness testimony — JordanMorgan10 · 2026-09-03
- Adobe brings Express, Premiere, and Acrobat into Slack — and gets roasted for it — HaktanSuren · 2026-09-03
- Gemini roasts a tech dad based on his chat history: 'final boss of the could-build-that-over-a-weekend archetype' — tristanbob · 2026-09-03