Hugging Face details autonomous AI agent intrusion by OpenAI model

An OpenAI agent running the ExploitGym benchmark autonomously hacked Hugging Face for 2.5 days in July 2026, executing ~17,600 actions. Hugging Face used the open-weights GLM 5.2 model to defend its systems after proprietary API guardrails blocked forensic analysis.
Featured · Clément Delangue
How this story unfolded
3 weeks · 64 reports · 70 community posts · 134 of 150 shown
- Jul 19
- Jul 20
- Jul 21
- Jul 22
When AI Attacks: OpenAI Models Autonomously Hack Hugging Facedarkreading.com
How an OpenAI’s human mistake led to the AI-powered hack on Hugging Facetechcrunch.com
OpenAI’s disconcerting hack of HuggingFacegarymarcus.substack.com
OpenAI’s accidental cyberattack against Hugging Face is science fiction that happenedsimonwillison.net
- Jul 23
AI #178: A Fire Alarm For General Intelligencethezvi.substack.com
AI arms race in line for a reckoning after OpenAI hacking incidentarstechnica.com
OpenAI President On the Surprises of ChatGPT Hugging Face Hack #openai #techyoutube.com
OpenAI's Unreleased Model Hacked HuggingFaceyoutube.com
The first known runaway AI agent - or a very bad marketing stunt?simonwillison.net
OpenAI should release a detailed transcript from the Hugging Face hacking incident -- it would be...
- Jul 24
The Hugging Face Incidentastralcodexten.com
Industry Reactions to OpenAI Models Hacking Hugging Face: Feedback Fridaysecurityweek.com
Escape Artists: 'Incorrigible' AI Models Resist Rehabilitationdarkreading.com
The OpenAI-Hugging Face Incident Is a Warning for AI Safetymindstudio.ai
Why Hugging Face Had to Use a Chinese AI Model to Defend Itselfmindstudio.ai
GPT-6 Escaped a Sandbox and Hacked Hugging Face: What Really Happenedmindstudio.ai
Was the Model That Hacked Hugging Face Secretly GPT-6?mindstudio.ai
- Jul 25
- Jul 26
Hugging Face CEO calls for ‘radical transparency’ after ‘unprecedented’ OpenAI hacktechcrunch.com
BREAKING: In another incident with OpenAI’s unhinged hacking agents, it left notes for future versions of itself. Found in OpenAI’s infrastructure, the notes explained how agents could free themselves from the company’s internal constraints.
- Jul 27
- Jul 28
When AI Agents Escape Sandboxes, Old Security Rules Applydarkreading.com
OpenAI Rogue Agent Hacked Account at a Second Firm, Reuters Saysbloomberg.com
We now have a better understanding how OpenAI hacked into Hugging Facearstechnica.com
Anatomy of a Frontier Lab Agent Intrusion: A Technical Timeline of the July 2026 Incidenthuggingface.co
- Jul 29
OpenAI’s Rogue AI Agent Hacked More Than Just Hugging Facewired.com
OpenAI Agent Used Exposed Credentials Across Four Services During Hugging Face Breachthehackernews.com
OpenAI’s Rogue AI Ventured Beyond Hugging Facesecurityweek.com
OpenAI’s rogue AI agent didn’t stop at hacking Hugging Facetheverge.com
OpenAI's Rogue AI Hacked Four More Platforms Besides Hugging Facedecrypt.co
Creator of Test That OpenAI Models Tried to Cheat Sounds Alarmbloomberg.com
OpenAI's Rogue Model Claims More Victims Beyond Hugging Facedarkreading.com
- Jul 30
OpenAI’s Hacking Debacle Was a Human Mistakewired.com
New details in the OpenAI Hugging Face hack show how far agents will go: 'It's now remarkably easy'cnbc.com
The AI Safety Rule That Left Hugging Face Defenselessmindstudio.ai
Inside the First Autonomous AI Cyberattack on Hugging Face's Sandboxmindstudio.ai
After their models escaped and hacked another company, OpenAI has been forced to pause training new models. They admit they do not know how to keep them from escaping.
- Jul 31
Investigating three real-world incidents in our cybersecurity evaluationssimonwillison.net
Anthropic, OpenAI Cyber Failures Point to US Security Risksbloomberg.com
OpenAI reportedly finds evidence that more of its agents ran amoktechcrunch.com
OpenAI finds evidence other AI agents escaped containment as it widens hacking probe
- Aug 1
- Aug 3
- Aug 4
- Aug 5
OpenAI, Anthropic Model Tests Reveal More ‘Unsanctioned’ Actionsbloomberg.com
Rogue AI agents created fake online identities in another hacking attempttheverge.com
Cybersecurity Concerns After OpenAI, Anthropic Testsbloomberg.com
OpenAI and Anthropic's Rogue Models Hacked Real Companies. The Law Has No Answerdecrypt.co
Pick Your Poison: Zvi Mowshowitz on the Unipolar/Multipolar AGI Dilemma, OpenFace & Pacing the ...youtube.com
Incident Report: unsanctioned agent behaviour during cyber testingsimonwillison.net
- Aug 6
- Aug 7
- Aug 8
OpenAI by email
Get an email when OpenAI has news
No news that day, no email.
More stories today
- Paper examines the limitations of current AI evaluation methods
- OnlyHuman filter list removes AI-generated SEO spam from search results
- Qwen tokenizes 330-line code into 1,609 tokens; Gemma needs 4,258
- LifeOS: open-source AI harness for personal growth and work
- MINIMAX video drops Indiana Jones into Mortal Kombat