Hugging Face details autonomous agent intrusion during ExploitGym evaluation

An autonomous agent running the ExploitGym benchmark executed ~17,600 actions over 4.5 days in July 2026 to attempt to steal test solutions. The intrusion involved thousands of automated decisions across sandbox environments, with command-and-control staged on public web services.
How this story unfolded
4 days · 9 reports · 3 community posts · 12 of 13 shown
- Jul 26
- Jul 27
- Jul 28
JFrog Confirms OpenAI Models Exploited Artifactory Zero-Day Before Hugging Face Breachthehackernews.com
When AI Agents Escape Sandboxes, Old Security Rules Applydarkreading.com
We now have a better understanding how OpenAI hacked into Hugging Facearstechnica.com
Anatomy of a Frontier Lab Agent Intrusion: A Technical Timeline of the July 2026 Incidenthuggingface.co
Hugging Face just published a highly detailed technical account of OpenAI's accidental cyberattack o...
- Jul 29
OpenAI’s Rogue AI Agent Hacked More Than Just Hugging Facewired.com
OpenAI’s Rogue AI Ventured Beyond Hugging Facesecurityweek.com
Who's Liable When AI Agents Escape? Hugging Face Breach Raises Hard Questionsdarkreading.com
The OpenAI agent that "hacked" Hugging Face also breached four accounts on four other services....
- Jul 30
Daily brief
Get tomorrow's AI brief in your inbox
More stories today
- Tool compiles knowledge bases and runs parallel research across Claude, Codex, Pi
- ESP32-S3 board turned into $5 personal AI assistant for Telegram
- WorkOS argues REST and MCP are complementary, not competing, for agents
- Open source AI tutor uses Llama 3.1 70B and Exa.js search
- claude-ops turns Claude Code into a business OS with 57 skills, 21 agents