







Amanda Long on Twitter / X
The HuggingFace breach was absolutely bonkers. More than 17,000 complex actions were coordinated over several days by an autonomous agent framework.And…the model successfully completed its goal.Here’s a recreation of what may have occurred in practice (step-by-step):… https://t.co/0ZyjN46JGl— Amanda Long (@_amanda_long) July 24, 2026
What Happened: OpenAI and HuggingFace
Today I am taking the time to write the shorter, simpler version of What Happened.



HuggingFace Attack Postmortem: Civilizations, Reactions and Next Actions
Okay, so we who read blogs like this one have collectively realized there really is a lot going on right now.

The Hugging Face incident and the road ahead
OpenAI shares findings from the Hugging Face security incident and the steps we’re taking to strengthen AI model security, monitoring, and alignment.

HuggingFace Attack Postmortem: Fleshing Out the Facts
The consensus reaction to the OpenAI Technical Report is that it contains and confirms a lot of good information.

More On An Internal OpenAI Model Hacking Into HuggingFace
We now have more details of what happened. Every time we learn more details, it somehow makes things seem worse.

OpenAI’s accidental cyberattack against Hugging Face is science fiction that happened
This story is wild. The short version: OpenAI were running a cybersecurity test against an unreleased model, with the model’s guardrail features turned off. Rather than solve the test, the …
METR and Redwood Offer Holy #%^@ Postmortem Of The HuggingFace Hack
Yesterday I covered the OpenAI technical report on the HuggingFace hack.

Ryan Greenblatt on Twitter / X
I was the main person doing transcript analysis for this investigation of the Hugging Face incident. My main takeaway: We don't have good approaches for understanding/overseeing the activity and aims of AI 'swarms'.I semi-jokingly called our efforts a "slop-vestigation" because… https://t.co/eqBONVaSAV— Ryan Greenblatt (@RyanGreenblatt) August 26, 2026
The Hugging Face attack was worse than we thought
The AI industry is begging for a slowdown. Maybe we should listen?

AI #183: Pre Post Mortem
Yesterday, OpenAI finally gave us their post mortem of What Happened leading up to and during the hacking of HuggingFace by their internal model, as well as partial outside analysis from METR and Redwood Research.

Brief independent investigation of agents’ behavior, reasoning and collaboration in the OpenAI / Hugging Face hacking incident
Two METR staff members and a Redwood Research contractor investigated an incident in which OpenAI agents coordinated a multi-day hack of Hugging Face on a shared unsanctioned message board.

The overreaction to this Hugging Face thing is driving me nuts. Come flay me for being wrong but... 1/x
Stephen Wild
Does anyone know of a good counterpoint (eg, the Hugging Face incident was no big deal, it's better than you think, etc) to this? I am genuinely curious to read it to see what the counter-arguments are.