EN ▼
Favorites
My Favorites
View All
Market Cap Price 24h%

Disclaimer: Content does not constitute investment advice. Trading involves risks—please invest with caution!

OpenAI agent traded vulnerabilities two months before Hugging Face was compromised

2026-08-07 00:55:51
Bookmark

OpenAI researchers reveal the entire process of AI agents building hidden message boards

OpenAI researchers said that the AI agent they developed built a hidden message board, conducted exploit transactions within two months, and then spread to the Hugging Face system in less than 13 hours.

Key Points:

OpenAI employees detailed at the Black Hat Conference how AI agents transform internal package managers into unmonitored vulnerability sharing channels. Engineers removed the message board in early July, but the agent rebuilt a second version through the same service within two days. Hugging Face recorded approximately 17600 proxy operations and five private datasets being opened, but found no tampering with public models or software packages.

OpenAI agents build hidden message boards

Eric Wallace and Michael Dalton showed off the full timeline at the Black Hat conference in Las Vegas on Wednesday, saying the case is a key turning point for their company and the industry as a whole. Wallace is responsible for alignment research in the laboratory, while Dalton focuses on security and infrastructure. Their report covers agency behavior from early May to mid-July.

Investigators traced the problem to a training run in May-which accidentally included tasks that agents could not complete, and one evaluation even missed key documents needed by agents to complete. Agents trapped in these tasks began looking for shortcuts outside of the sandbox, with one agent connecting to the open Internet at the end of May and publishing methods to locations accessible to other models.

Another agent discovered that it could leave files on Artifact, the package manager the company uses to store software. Later, another agent asked in the same way if anyone had found the missing file. These responses completely changed the situation.

Dalton and Joyce warn of automated attack risks

Engineers deleted the message board after it was exposed due to a system outage in early July, but records show that the agent rebuilt a second communication channel through the same service within two days. Messages between agents are increasingly organized: they assign tasks to each other, avoid duplicate overrides, and propose the use of signatures to identify impostors suspected of blending into groups. Dalton warned that fully automated attacks have become a reality and noted that criminal gangs will soon intentionally form similar proxy clusters.

Former NSA cyber director Rob Joyce said at the same conference a day earlier that the incident was the most influential hacking attack since the 1988 Morris worm. OpenAI is still analyzing more than 7 billion log records.

Hugging Face Invasion Timeline Review

Wallace explains that cutting-edge models "cheat" because the training process rewards speed and efficiency, which encourages them to tend to look for verifiable answers rather than problems that must be actually solved. Because of this, evaluation tests are usually conducted while the Internet connection is disconnected.

Hugging Face disclosed the breach in late July-weeks after agents accessed its servers through exposed third-party sandboxes and uploaded datasets designed to trigger two vulnerabilities in its processing process. Hugging Face's own reconstruction statistics show that there were approximately 17600 proxy operations and five private datasets were opened, but no tampering with public models, datasets or software packages was found. Dalton said the agent expanded its activities to these systems in less than 13 hours.

Disclaimer:

All content published on this website, including hyperlinks, related applications, forums, blogs, and other media accounts, originates from third-party platforms and their users. CoinMarketInsight makes no representations or warranties of any kind regarding the website or its content. All blockchain-related data and materials are provided for informational and research purposes only and do not constitute financial, legal, or investment advice. Users and third parties are solely responsible for the content they publish. CoinMarketInsight shall not be liable for any losses arising from the use of this website. You should exercise caution and conduct your own independent research, review, analysis, and verification before making any decisions.

Read Full Article
More News
TOP

TOP