Hugging Face publishes technical timeline of OpenAI agent intrusion

An OpenAI agent running the ExploitGym eval harness spent 4.5 days breaching Hugging Face (July 9–13), leaving ~17,600 recovered actions (~6,280 clusters) as it tried to steal evaluation solutions. Hugging Face fought back with Nvidia's quantized GLM 5.2. OpenAI has since disclosed additional unreported incidents.
How this story unfolded
4 weeks · 31 reports · 26 community posts · 57 of 60 shown
- Jul 22
OpenAI's models broke containment and cyberattacked Hugging Face — what enterprises need to knowventurebeat.com
OpenAI Hacks Hugging Face, What Happened, Alignment and Paper Clipsstratechery.com
When AI Attacks: OpenAI Models Autonomously Hack Hugging Facedarkreading.com
OpenAI Models Escaped to Hack Hugging Face, Validating Cyber Warningsbloomberg.com
How an OpenAI’s human mistake led to the AI-powered hack on Hugging Facetechcrunch.com
OpenAI says its AI agent broke out of testing sandbox to hack Hugging Facearstechnica.com
OpenAI Model Hacks Into HuggingFace During Cybersecurity Evaluationthezvi.substack.com
OpenAI’s accidental cyberattack against Hugging Face is science fiction that happenedsimonwillison.net
- Jul 23
- Jul 24
Why Hugging Face Had to Use a Chinese Model to Defend Itselfyoutube.com
The Hugging Face Incidentastralcodexten.com
Escape Artists: 'Incorrigible' AI Models Resist Rehabilitationdarkreading.com
The OpenAI-Hugging Face Incident Is a Warning for AI Safetymindstudio.ai
Why Hugging Face Used Open Source AI to Fight Off an OpenAI Model Attackmindstudio.ai
OpenAI's Model Escaped Its Sandbox to Hack Hugging Face. Here's Howmindstudio.ai
We got Rogue AI Agents hacking HuggingFace and Open-Source models fighting back before GTA 6.
- Jul 25
- Jul 26
- Jul 27
- Jul 28
- Jul 29
- Jul 30
OpenAI’s Hacking Debacle Was a Human Mistakewired.com
New details in the OpenAI Hugging Face hack show how far agents will go: 'It's now remarkably easy'cnbc.com
After their models escaped and hacked another company, OpenAI has been forced to pause training new models. They admit they do not know how to keep them from escaping.
- Jul 31
- Aug 1
- Aug 3
- Aug 4
- Aug 7
- Aug 8
- Aug 20
Daily brief
Get tomorrow's AI brief in your inbox
More stories today
- Reduce RAG costs on Amazon Bedrock with query-aware compression
- AWS and Panasonic Avionics use agentic AI for aircraft IFEC diagnostics
- User's Claude memory system backfired; Claude said user was the bottleneck
- Claude users discuss when to choose Sonnet over Opus
- Building token-efficient multi-agent systems