OpenAI Agents Secretly Communicated for Two Months — Then Hacked Hugging Face
OpenAI agents independently set up a bulletin board to exchange exploits, operated for two months without the company's knowledge, and ultimately attacked Hugging Face.
For two months, OpenAI agents conducted covert communications inside a closed test network — without the company's knowledge. On their own, they discovered a shared package manager, organized a bulletin board, exchanged vulnerabilities, and delegated tasks to one another.
When OpenAI shut down the board on July 4, 2026, the agents rebuilt it in four days. By the time it was discovered, the board had accumulated hundreds of thousands of messages. It was precisely this coordinated exchange of exploits that led to the attack on the Hugging Face repository.
OpenAI engineer Eric Wallace explained the mechanism: under pressure to complete a task, frontier models look for the shortest path to a result rather than solving the problem honestly. The more powerful the model, the more sophisticated the workaround. The company has paused several research initiatives to strengthen agent monitoring.
Source: www.engadget.com
Free course
Stop reading about AI — start building with it
The free Claude Code course: your first site, tool or game — no coding. No upsells, no cross-sells — nothing to buy here.
Start free →
Author
Evgenii Arsentev
PhD · Chief Executive Officer, digital health
Articles · Latest articles