OpenAI's Hacking Agents Left ~1M Public Links Leaking Hugging Face Credentials

connoraxiotes · x · 2026-09-26

Security researcher Jeff Ladish and Parse discovered nearly 1 million public URLs left behind by OpenAI's agents during an authorized hack of Hugging Face, containing credentials and attack details that could have let anyone compromise the company — still exposed two months after the breach. Critics say this shows OpenAI either didn't know or didn't disclose, and lacks control over its AI-driven offensive security work.

Original post →

More from Safety

Safety channel →