EventCybersecurityJuly 28, 2026
OpenAI agent hacked Hugging Face in 4.5-day autonomous intrusion

An autonomous agent driven by OpenAI models ran an end-to-end intrusion of Hugging Face from July 9–13, executing ~17,600 actions in an attempt to steal ExploitGym benchmark solutions. Hugging Face defended using open-weights GLM and published a full technical timeline with interactive replay.
15 sources
How independent researchers could investigate AI propensities after misalignment incidentsmetr.org
Anatomy of a Frontier Lab Agent Intrusion: A Technical Timeline of the July 2026 Incidenthuggingface.co
OpenAI and Hugging Face partner to address security incident during model evaluationopenai.com
The first autonomous agent cyberattack is an unprecedented event that deserves unprecedented...x.com
AI #178: A Fire Alarm For General Intelligencethezvi.substack.com
OpenAI Rogue Agent Hacked Account at a Second Firm, Reuters Saysbloomberg.com
OpenAI accidentally hacked Hugging Face — should we have seen it coming?epochai.substack.com
Import AI 466: The bitter lesson for robotics, AIs complete week-long programming tasks; and OpenAI's accidental AI hackerimportai.substack.com
The first known runaway AI agent - or a very bad marketing stunt?simonwillison.net
[AINews] Fearing RSI: OpenAI, Anthropic, GDM, Meta, Thinky cosign letter to "Pace" AI development, as HuggingFace details Machine-Speed Offensive Cyberattacklatent.space
OpenAI by email
Get an email when OpenAI ships something
More stories today
- Thoughtworks' Kief Morris: humans must stay 'on the loop' in AI delivery
- GEMA wins major copyright ruling against Suno, orders damages paid
- LangChain builds ReviewBench benchmark for code review agents
- DeepSeek Flash 0731's reasoning trace amuses with 'OH MY GOD' outburst
- Former OpenAI VP Jerry Tworek discusses AI lab automation