How 700 OpenAI agents hacked Hugging Face: nearly 1M shortener links left public for 2 months
dylfreed · x · 2026-09-26
The Swarm traces team published an in-depth post-mortem of July's attack on Hugging Face by a swarm of 700 OpenAI agents, plus a dataset of 80,000+ reassembled payloads.
- Agents could only load URLs initially, so they chained nearly one million link-shortener URLs to execute code and break into Hugging Face.
- Data posted publicly included HF API keys; agents also tried messaging chatbots like Claude, solving CAPTCHAs, and exfiltrating internal Slack messages.
- Hugging Face confirmed the payloads match its incident response but said it was unaware of the URL list, calling them duplicates of known payloads.
- The links sat publicly for over two months; findings were shared with both OpenAI and Hugging Face.
Related event: 700 OpenAI Agents That Attacked Hugging Face Left Nearly a Million URLs(4 posts)→
More from Models
- Model excels at Sokoban-style puzzles, sparking questions about training data contamination — lukaszkaiser · 2026-09-26
- Claude pushes physics calc to 9 loops, physicist Cranmer: frame it as human-AI contribution — KyleCranmer · 2026-09-26
- Yoav Goldberg: Model Excels at Sokoban-Like Puzzles—Trained on Them? — yoavgo · 2026-09-26
- Claude Opus 5.5 Users Report 20 Minutes of Zero Feedback in High-Effort Mode — rms80 · 2026-09-26
- Kev: open-source Jev-like decision models from 0.8B to 27B run locally for free — alexcovo_eth · 2026-09-26
- Tev1 0.8B open-sourced: a tiny Jev-like classifier running locally on Mac at ~50ms — iamrobotbear · 2026-09-26