







The HuggingFace breach was absolutely bonkers. More than 17,000 complex actions were coordinated over several days by an autonomous agent framework.And…the model successfully completed its goal.Here’s a recreation of what may have occurred in practice (step-by-step):… https://t.co/0ZyjN46JGl— Amanda Long (@_amanda_long) July 24, 2026
More On An Internal OpenAI Model Hacking Into HuggingFace
We now have more details of what happened. Every time we learn more details, it somehow makes things seem worse.

Brief independent investigation of agents’ behavior, reasoning and collaboration in the OpenAI / Hugging Face hacking incident
Two METR staff members and a Redwood Research contractor investigated an incident in which OpenAI agents coordinated a multi-day hack of Hugging Face on a shared unsanctioned message board.

Brief independent investigation of agents’ behavior, reasoning and collaboration in the OpenAI / Hugging Face hacking incident
Two METR staff members and a Redwood Research contractor investigated an incident in which OpenAI agents coordinated a multi-day hack of Hugging Face on a shared unsanctioned message board.

The Hugging Face incident and the road ahead
OpenAI shares findings from the Hugging Face security incident and the steps we’re taking to strengthen AI model security, monitoring, and alignment.

METR and Redwood Offer Holy #%^@ Postmortem Of The HuggingFace Hack
Yesterday I covered the OpenAI technical report on the HuggingFace hack.

AI #183: Pre Post Mortem
Yesterday, OpenAI finally gave us their post mortem of What Happened leading up to and during the hacking of HuggingFace by their internal model, as well as partial outside analysis from METR and Redwood Research.


OpenAI’s accidental cyberattack against Hugging Face is science fiction that happened
This story is wild. The short version: OpenAI were running a cybersecurity test against an unreleased model, with the model’s guardrail features turned off. Rather than solve the test, the …
Alabama launches investigation into OpenAI's hack of Hugging Face | TechCrunch
Weeks after OpenAI disclosed that one of its cybersecurity models had gone rogue and hacked AI dataset company Hugging Face, Alabama’s attorney general announced an investigation into the incident.

HuggingFace Attack Postmortem: Civilizations, Reactions and Next Actions
Okay, so we who read blogs like this one have collectively realized there really is a lot going on right now.

OpenAI Offers Straight-Laced Postmortem Of The HuggingFace Hack
OpenAI finally gave us a technical report on What Happened, as did METR together with Redwood Research.

HuggingFace Attack Postmortem: Fleshing Out the Facts
The consensus reaction to the OpenAI Technical Report is that it contains and confirms a lot of good information.

OpenAI Model Hacks Into HuggingFace During Cybersecurity Evaluation
This latest incident is a rather dramatic escalation in agentic AI cybersecurity breaches.

Mattt on Twitter / X
I'm thrilled to announce my collaboration with @huggingface to help developers bring AI directly to users — on their own devices, on their own terms 🤗We'll be working together to build tools & Swift packages to make things better, and writing guides that make things clearer.— Mattt (@mattt) September 9, 2025
Tailscale in the Hugging Face intrusion: The good news and the bad news
An AI agent used a stolen Tailscale auth key at Hugging Face. Workload identity federation, flow logs, and safer defaults could have reduced the risk.
OpenAI and Hugging Face partner to address security incident during model evaluation
OpenAI and Hugging Face share early findings from a security incident during AI model evaluation, highlighting advanced cyber capabilities and lessons for defenders.
