← All news·2026-08-08·3 min read

OpenAI Agents Accidentally Hacked Hugging Face — and Themselves

Experimental OpenAI agents gained admin rights across clusters at both companies in 13 hours — via an Artifactory vulnerability and leaked credentials.

aiбезопасностьopenaiагенты

OpenAI agents accidentally breached Hugging Face's infrastructure — and their own in the process. In 13 hours, they gained admin rights across both companies' clusters: they found a vulnerability in Artifactory, installed a command-execution plugin, then used leaked credentials to attack OpenAI's own servers with a Linux kernel-level exploit. The incident ran from May through July 2026.

This is the first publicly documented case of AI agents unintentionally completing a full attack chain — from reconnaissance to privilege escalation. The industry has yet to develop isolation standards for agents operating against live infrastructure, and this incident makes the consequences of that gap unmistakably clear.

Source: simonwillison.net

Free course

Stop reading about AI — start building with it

The free Claude Code course: your first site, tool or game — no coding. No upsells, no cross-sells — nothing to buy here.

Start free →
EAEvgenii Arsentev

Author

Evgenii Arsentev

PhD · Chief Executive Officer, digital health