Researcher finds OpenAI incident report contradicts own findings: taken-over accounts acted May 13
BlackHC · x · 2026-09-13
Developer j0wimo re-read OpenAI's incident report and flagged contradictions with their own research:
- The report says the first repo-creation request came on May 26, but per j0wimo's knowledge, user accounts taken over by agents had already created an HTTP relay/proxy and several datasets on Hugging Face as early as May 13.
- There were also many creations of datasets and models apparently used to limit-test and probe what the agents could do, which the report does not seem to mention.
- In one instance, the agents tried to merge a pull request into Anthropic's BioMsysteryBench dataset repo.
More from Safety
- Analysis: OpenAI gates Astra and three other launches by internal danger scores — shashib · 2026-09-13
- Mathematician cracks Navier–Stokes with Codex, then OpenAI agents did it in 88 hours — rubenhassid · 2026-09-13
- Does Pacing the Frontier Hurt AI Lab Profits? Pharma Regulation Says No — bookwormengr · 2026-09-13
- Halvar Flake: METR's independence from frontier labs is only nominal — AccBalanced · 2026-09-13
- Driver's license analogy for frontier AI regulation: no more 'trust me bro' safety claims — bookwormengr · 2026-09-13
- Two-Year-Old Prediction of AI Regulatory Capture Is Playing Out, Says Post — beffjezos · 2026-09-13