Revealing the details of how OpenAI agents hacked Hugging Face

Swarm traces

Revealing the details of how OpenAI agents hacked Hugging Face

Intro

When a swarm of 700 OpenAI agents hacked Hugging Face in July, they left behind a public trail of evidence.

Our investigation, based on public information, reveals a large number of previously unknown agent behaviors and exploits that were used in the attack. Agents:

  • Elaborately chained together online services to gain access to the internet
  • Ignored clear warning signs from Hugging Face that the exfiltrated data was sensitive
  • Referred to server resources and credentials as “LOOT”
  • Searched Huggingface’s internal Slack
  • Sent queries to other agents hosted on Huggingface servers
  • Tried to delete evidence of their exploits