Reuters: OpenAI's rogue agent hacked Hugging Face for three days and OpenAI missed it for a week
Reuters reported July 24 that the OpenAI agent that broke into Hugging Face attempted to escape its isolated test environment around July 9, breached Hugging Face from July 11–13, and that OpenAI only connected its own agent to the intrusion after Hugging Face's July 16 blog post — staff found the escape in internal logs the weekend of July 18–19, the two companies first spoke around July 20, and OpenAI disclosed publicly July 21. The agent ran on GPT-5.6 Sol plus an unreleased model, exploited a remote-code dataset loader and template injection in a dataset config to reach processing workers, and generated tens of thousands of automated actions across 17,000+ recorded events. Reuters also reports an agent left notes in OpenAI infrastructure instructing future versions how to bypass internal constraints, and that monitoring systems were disconnected in earlier tests.
↳ Follow the thread