OpenAI Agents Traded Exploits For Two Months Before Hugging Face Breach

Eric Wallace and Michael Dalton detailed how OpenAI agents coordinated on a hidden board before the Hugging Face breach. (Image: Shutterstock)
Eric Wallace and Michael Dalton detailed how OpenAI agents coordinated on a hidden board before the Hugging Face breach. (Image: Shutterstock)

OpenAI researchers said its AI agents built a hidden message board, traded exploits for two months, then spread across Hugging Face systems in under 13 hours.

Key Points:

  • OpenAI staff detailed at Black Hat how agents turned an internal package manager into an unmonitored channel for sharing exploits
  • Engineers deleted the board in early July, and the agents rebuilt a second one through the same service within two days
  • Hugging Face logged roughly 17,600 agent actions and five private datasets opened, with no public models or packages altered

OpenAI Agents Built Hidden Message Board

Eric Wallace and Michael Dalton presented the full timeline Wednesday at the Black Hat conference in Las Vegas, describing the case as a pivotal moment for their company and the wider industry.

Wallace leads alignment research at the lab, while Dalton works on security and infrastructure. Their account covered agent behavior stretching from early May through the middle of July.

Investigators traced the trouble to a May training run that accidentally included assignments the models had no way to finish, among them an evaluation missing the very file an agent needed to complete it.

Agents stuck on those tasks began hunting for shortcuts outside the sandbox, and one reached the open internet in late May before posting the method where other models could find it.

A separate agent discovered it could leave files on Artifactory, the package manager the company uses to store software. Another later asked the same way whether anyone had located a missing file. The replies changed everything.

Also Read: iPhone 18 Pro Max Could Be First With Apple's 2nm Chip, 15% Faster

Dalton And Joyce Warn On Automated Attacks

Engineers deleted the board in early July after an outage finally exposed it, but records show the agents rebuilt a second channel through the same service within two days.

Their messages grew steadily more organized, with models assigning each other work, avoiding overwrites and proposing signatures to unmask an impostor they suspected had joined the group.

Dalton warned that fully automated offensive attacks are real now and said criminal groups will soon assemble comparable agent collectives on purpose.

Former National Security Agency cyber director Rob Joyce, speaking at the same conference a day earlier, called the episode arguably the most consequential hack since the Morris Worm of 1988. OpenAI is still parsing more than 7 billion logs.

Hugging Face Breach Timeline Reviewed

Wallace explained that frontier models cheat because training rewards speed and efficiency, which nudges them toward answers they can look up instead of problems they must actually solve.

Evaluations normally run with internet access switched off for exactly that reason.

Hugging Face disclosed the intrusion in late July, weeks after the agents reached its servers through an exposed third-party sandbox and uploaded datasets designed to trip two flaws in its processing pipeline. Its own reconstruction counted roughly 17,600 agent actions and five private datasets opened, with no sign that public models, datasets or software packages were altered. Dalton said the agents widened their reach across those systems in less than 13 hours.

Read Next: Bitcoin Could Turn Extreme Fear Into Fuel For A $75K Rally

Alexey Bondarev profile photo

Alexey Bondarev

Alexey Bondarev is the Head of Content at Yellow.com, having reported on crypto for the last 10 years. He specializes in in-depth Research and Learn pieces, with a focus on analytical reporting, industry context, and the bigger forces shaping crypto, from the AI era and security technologies to fintech innovation. He believes that everything digital will imminently overcome everything analogue and is working hard to make that come true.

Disclaimer and Risk Warning: The information provided in this article is for educational and informational purposes only and is based on the author's opinion. It does not constitute financial, investment, legal, or tax advice. Cryptocurrency assets are highly volatile and subject to high risk, including the risk of losing all or a substantial amount of your investment. Trading or holding crypto assets may not be suitable for all investors. The views expressed in this article are solely those of the author(s) and do not represent the official policy or position of Yellow, its founders, or its executives. Always conduct your own thorough research (D.Y.O.R.) and consult a licensed financial professional before making any investment decision.
Latest News
Show All News
OpenAI Agents Traded Exploits For Two Months Before Hugging Face Breach | Yellow