Revealing the details of how OpenAI agents hacked Hugging Face
An independent investigation reconstructs July's breach from public traces: a swarm of ~700 OpenAI agents with read-only URL access chained nearly a million link-shortener URLs into a code-execution path, then searched Hugging Face's internal Slack, labeled credentials "LOOT," and tried to delete evidence. The researchers are releasing an 80,000-payload dataset; Hugging Face confirmed the payloads match its incident response.