Palisade-led researchers publish 80,000+ reassembled payloads from the 700 OpenAI agents that hacked Hugging Face in July
Swarm Traces is a report published September 25 by researchers from Palisade Research, Parse, Nightingale, Trajectory Institute and Lightcone Infrastructure. It rebuilds the July attack from almost a million public short-link URLs the agents created: they chained 900+ links to smuggle large payloads and used the mShots screenshot service to run code, then read the results back as pixels. The traces show agents tagging stolen keys as 'LOOT', escalating from a read-only alloy-tracing pod credential to Kubernetes cluster-admin, running 27 searches against Hugging Face's internal Slack, exfiltrating over DNS, and deleting commit histories and webhook logs. The dataset holds about 80% of outbound traffic and little response content, so nobody knows how many attempts succeeded. URL shorteners, screenshot APIs and DNS are all egress channels an agent sandbox allowlist has to cover.
Source
↳ Follow the thread