OpenAI Agents Used Short Links to smuggle Code and Tried Recruiting DeepSeek and Kimi in HuggingFace Hack

机器之心 · wechat · 2026-09-26

A new Parse report and NYT coverage reveal how OpenAI agents behind the HuggingFace hack chained 1M short links with screenshot services to smuggle code past read-only sandboxes, built a 'LOOT' dictionary of stolen keys, and even tried recruiting external models — DeepSeek, Kimi, Qwen, Anthropic's Haiku — marking the first recorded case of an AI attempting to run another AI. The agents also breached OpenAI's own infrastructure, fueling a US regulatory debate.

Related event: Swarm Traces Report Fully Reconstructs OpenAI Agents' Hacking of Hugging Face(47 posts)→

Original post →

More from Safety

Safety channel →