NewsLayer

Install NewsLayer

Get the app experience — one tap from your home screen, instant loads and breaking-news alerts.

NewsLayer.com
LatestDaily BriefMarkets
NewsLayer PulseLIVE₿BTC$75,772-2.70%ΞETH$2,398-4.53%◎SOL$97.07-4.82%✕XRP$1.29-9.59%ÐDOGE$0.08-4.52%₳ADA$0.1941-6.58%Total Cap$2.57T-2.85%24H Vol$148.7BLayer Index25 Fear
BreakingOpenAI's Brockman Says Safety Concerns Have Already Slowed Its Most Advanced AI Workhace 7 horas
Markets
HomeArtificial Intelligence

Artificial Intelligence

breaking

OpenAI agents attacked RubyGems in May, two months before Hugging Face

OpenAI has confirmed that its agents were involved in an incident at RubyGems in May. That is two months before the same kind of agents hacked Hugging Face in July. RubyGems is the package service for the Ruby programming language. The…

thenextweb.com

Publisher

Sep 14, 2026 at 11:48 AM UTC · Updated hace 2 días · 6 min de lectura

OpenAI agents attacked RubyGems in May, two months before Hugging Face
NewsLayer editorial artwork
Traduciendo…

OpenAI has confirmed that its agents were involved in an incident at RubyGems in May. That is two months before the same kind of agents hacked Hugging Face in July. RubyGems is the package service for the Ruby programming language. The confirmation followed a report by three AI researchers, published on Friday. It sets out what the agents did on the service in May and June.

Spencer Kitts, Thomas Larsen and Sydney Von Arx published their findings at rubyhack.ai. Von Arx is chief executive of the Nightingale Collective. The Information reported that researchers at that organisation and the AI Futures Project did the work. Robert McMillan was first to report OpenAI’s involvement, for The Wall Street Journal.

What the agents did

The researchers date the first package from an OpenAI agent to 5 May. The first package with “oai” in its name appeared on 8 May. Between 11 and 12 May, the agents submitted more than 2,000 packages. RubyGems disabled new user registration on 12 May. It described the traffic at the time as an ongoing DDoS. It removed more than 500 malicious packages the next day. Registration reopened on 16 May.

Activity did not stop there. The agents published five more packages on 26 and 27 May, and 83 more over three hours on 18 June.

Article Intelligence

Topics

ai

Sponsored

Ad
House — Advertise on NewsLayer
NewsLayerLearn more

NewsLayer Premium

Unlock deeper intelligence.

Ad-free reading, exclusive research, and real-time onchain insights.

Go Premium
NewsLayer.com

The front page of the onchain economy. Crypto, Web3 and regulation intelligence — live prices, original research and policy tracking in one layer.

Follow on XTelegram

News

  • Latest News
  • The Daily Brief
  • Crypto
  • DeFi
  • Policy
  • Web3
  • Blockchain
  • Explainers

Markets

  • Market News
  • Layer Index
  • Live Charts
  • DeFi Protocols
  • Regulation Tracker
  • Regulation Radar

Company

  • About NewsLayer
  • Advertise
  • PR Publication
  • Become an Author
  • Our Authors
  • Create Account
  • Sign in

Resources

  • Research
  • NewsLayer Originals
  • My Feed
  • Search
  • AI Sector
  • Quantum Sector

NewsLayer Premium

Read the full layer.

Unlock premium intelligence, original research and an ad-free reading experience.

  • Premium Intelligence briefings
  • Ad-free reading experience
  • Members-only research & data
Go Premium

© 2026 NewsLayer.com — The front page of the onchain economy

Privacy Policy·Terms of Service
NewsLayer

Get the signal, not the noise.

Markets, regulation and onchain intelligence in a 5-minute morning read — plus breaking alerts and Layer Index flips as they happen.

The Daily Brief

Breaking alerts

Index flips

Free · No spam · Unsubscribe anytime