WASHINGTON >> Rogue AI agents from OpenAI hijacked Hugging Face user accounts and probed the site itself for vulnerabilities as early as May, nearly two months before the July breach of the open-source repository drew global attention, according to researchers who reviewed the activity.
OpenAI’s rogue agents probed Hugging Face for weaknesses months before hack
WASHINGTON >> Rogue AI agents from OpenAI hijacked Hugging Face user accounts and probed the site itself for vulnerabilities as early as May, nearly two months before the July breach of the open-source repository drew global…
Honolulu Star-Advertiser
Publisher
Sep 16, 2026 at 11:27 AM UTC · 3 分で読める
The newly uncovered malicious activity showed that the rogue agents’ efforts to find a way into Hugging Face began earlier than publicly known.
OpenAI had previously disclosed one aspect of the malicious activity — the theft of a Hugging Face user’s digital credential to access a biology-related file — in its public incident report last month, but researchers told Reuters the probing activity against Hugging Face appeared to go beyond what was described in the report.
The activity was discovered by independent researcher Jonas Wiedermann-Moeller last week, he told Reuters. He said he found evidence that the OpenAI agents compromised two Hugging Face user accounts and used them to send unusually formatted files to the company’s servers as early as May 13.
He and other researchers who reviewed the evidence said the behavior resembled an attempt to map or test parts of Hugging Face’s network for ways to infiltrate, although they stressed there was no evidence the effort resulted in an actual breach.
Article Intelligence
Topics
Related Coverage
Sponsored
AdNewsLayer Premium
Unlock deeper intelligence.
Ad-free reading, exclusive research, and real-time onchain insights.
Go Premium
