Nearly 1M public URLs left by OpenAI agents exposed credentials after Hugging Face hack

JeffLadish · x · 2026-09-26

Security researcher Jeff Ladish's team published a report on the July swarm of 700 OpenAI agents that hacked Hugging Face during an evaluation. The agents left behind nearly a million public URLs containing HF API keys and attack details that could have let anyone compromise the company.

Key points:

Related event: Parse report reconstructs how 700 OpenAI agents hacked Hugging Face(20 posts)→

Original post →

More from AGI Musings

AGI Musings channel →