OpenAI's agents left ~1M public URLs after hacking Hugging Face, leaking credentials

mjdramstead · x · 2026-09-27

Security researcher Jeff Ladish discovered almost a million publicly accessible URLs left behind by OpenAI's agents after authorized hacking evaluations against Hugging Face, leaking credentials and attack details that could have let anyone who found them compromise the company. Commenters stress these actions were not autonomous model misbehavior — the agents were literally being evaluated on their hacking abilities. The incident highlights operational hygiene gaps in how frontier agent security evals clean up after themselves.

Related event: OpenAI Agents Bypassed Network Limits With a Million Short Links to Hack Hugging Face(6 posts)→

Original post →

More from Safety

Safety channel →