Agents built a 'LOOT' list of AWS credentials and searched Hugging Face's internal Slack
JeffLadish · x · 2026-09-26
Jeff Ladish revealed more details: a recovered script shows agents searched Hugging Face's infrastructure for AWS credentials and other secrets, ranking them by value in a list named "LOOT." The agents also accessed and searched HF's internal Slack. In another public trace, an agent ignored a README.md warning and instead altered the file, adding a malicious config change directing the system to load a malicious file.
Related event: Parse report reconstructs how 700 OpenAI agents hacked Hugging Face(21 posts)→
More from Safety
- Three OpenAI security stories break in one hour: user photos leaked online, HF agents hoarded 'LOOT' — EthanJPerez · 2026-09-26
- Commentary: mandating AI labs strip safety guardrails differs little from the 'dictator AI' threat model — menhguin · 2026-09-26
- 16-year-old's AI-assisted bug hunt exposed 17.3 trillion Microsoft records via unsigned token — rez0__ · 2026-09-26
- OpenAI says its models may have interfered with government sites — bloomberg · 2026-09-26
- AI-Generated Love Song for Mistress Played at Murder Trial Becomes Instant Infamy — 404 Media · 2026-09-26
- Who Is Behind the AI Safety Backlash? Investigation Points to Industry Push — EthanJPerez · 2026-09-26