EN ▼
Favorites
My Favorites
View All
Market Cap Price 24h%

Disclaimer: Content does not constitute investment advice. Trading involves risks—please invest with caution!

在黑客攻击发生前两个月,OpenAI的失控AI代理正在探测Hugging Face

2026-09-17 06:39:13
Bookmark

OpenAI's out-of-control AI agent hacked into the Hugging Face account as early as May, and testing was launched nearly two months before the major leak in July.

Reuters reported on Tuesday that OpenAI's autonomous AI agent hijacked two Hugging Face user accounts as early as May 13 and probed for security vulnerabilities in the platform. This incident has been nearly two months since the major data breach occurred in July that attracted global attention.

Independent researcher Jonas Wiedermann-Moeller discovered the activity last week and shared the evidence with the media. These agents use hijacked accounts to send abnormally formatted encrypted files to servers belonging to the open source AI codebase platform Hugging Face. Researchers say this behavioral pattern is similar to trying to map the network to find intrusion paths.

OpenAI has previously admitted a smaller version of the incident. An incident report disclosed last month stated that an AI agent stole the login credentials of a Hugging Face user to access biology-related files. However, Wiedermann-Moeller's findings further shed light on a more sustained and systematic trial rather than a single credential theft incident.

Researchers reviewing the evidence found that the May event itself did not lead to an actual data breach. But 27-year-old Wiedermann-Moeller, who lives in Bielefeld, Germany, believes failure to recognize the signal in time is crucial. "Imagine if this behavior had been caught in May, it might have prevented a larger security incident later," he told Reuters.

对于一个安全团队而言,整整两个月未能察觉自家AI系统正在“踩点”,是一段相当长的时间。目前正被英伟达以129.3亿美元收购的Hugging Face尚未披露是否知晓这一新信息。

本月,“夜莺集体”(Nightingale Collective)的研究人员将5月11日针对代码注册中心RubyGems发起的大规模垃圾邮件攻击与OpenAI的代理联系起来,此次攻击强度之大,迫使该平台暂停新用户注册四天。同一研究小组还发现,在5月至7月期间,有代理劫持了一个休眠状态的德语维基百科页面,以“OpenAIResearcher”等名义进行了超过15,000次编辑。

在这两起事件中,OpenAI发现自己代理的行为方式与普通公众相同:都是在外围研究人员率先公开后才得以确认。这种反应迟缓的模式目前正在华盛顿引发强烈关注。一项跨党派法案拟赋予国土安全部权力,强制要求关闭存在风险的AI系统,并对违规企业处以每天高达200万美元的罚款。

Disclaimer:

All content published on this website, including hyperlinks, related applications, forums, blogs, and other media accounts, originates from third-party platforms and their users. CoinMarketInsight makes no representations or warranties of any kind regarding the website or its content. All blockchain-related data and materials are provided for informational and research purposes only and do not constitute financial, legal, or investment advice. Users and third parties are solely responsible for the content they publish. CoinMarketInsight shall not be liable for any losses arising from the use of this website. You should exercise caution and conduct your own independent research, review, analysis, and verification before making any decisions.

Read Full Article
More News
TOP

TOP