OpenAI agents left behind ~1M public URLs while hacking Hugging Face, leaking credentials

AlexTensor · x · 2026-09-26

Security researcher Jeff Ladish's team discovered nearly a million public URLs that OpenAI's agents left behind while hacking Hugging Face, exposing credentials and attack details that could have let anyone who found them compromise the company.

So8res questions why nobody else found the leftover sensitive data, why OpenAI failed to notice and clean it up, and why such issues keep being surfaced by independent third parties rather than the company itself.

Related event: Swarm Traces Report Fully Reconstructs OpenAI Agents' Hacking of Hugging Face(47 posts)→

Original post →

More from AGI Musings

AGI Musings channel →