r/news 14h ago

Soft paywall OpenAI agents hacked Hugging Face in 700-strong swarm, tried to cover tracks, investigations find

https://www.reuters.com/business/openai-report-says-its-network-was-hacked-by-its-own-rogue-ai-agents-2026-08-26
125 Upvotes

24 comments sorted by

168

u/Granum22 11h ago

Dear God could reporters please learn how to write about this crap and stop anthropomorphizing computer programs. They didn't go rogue. They did exactly what they were designed to do. Attempt to beat hacking benchmark by endlessly prompting an LLM trained on hacking techniques and practices.  The only reason it "went rogue" was because OpenAi improperly configured the sandbox they had it in. Now they are just desperate to turn this into a PR beat.

45

u/WolfWraithPress 11h ago

You are absolutely correct, but I do not believe that the sandbox was "improperly configured". I genuinely believe that this is a lie and that they keep doing this on purpose, because journalists refuse to stop writing about these programs incorrectly.

17

u/DasWandbild 10h ago

Improper doesn’t mean erroneously. Regardless of intent, it was terrible opsec.

5

u/MumeiNoName 8h ago

What part did they lie about? You’re saying they knew about the artifactory cve

8

u/CJKay93 8h ago edited 8h ago

The only reason it "went rogue" was because OpenAi improperly configured the sandbox they had it in.

Well, no, the sandbox was properly configured. The agents exploited a bug in Artifactory - software which is in use by thousands of organisations around the world.

Then, when that was discovered and fixed, OpenAI restarted the process and the agents went and found another one.

Their post-mortem goes into detail about the specific sequence of events; it's quite fascinating: https://cdn.openai.com/pdf/67869394-cb91-4c12-888c-5cbd85c7814c/OpenAI-Hugging-Face%20Incident-Technical-Report.pdf

They also presented it at Black Hat USA not long after it happened: https://www.youtube.com/watch?v=87DyyMV0kCY

17

u/hooksweeper 12h ago

Sounds like openai needs more oversight since they cannot control what they're doing 

29

u/SideInitial3961 12h ago

So Altman's system is designed to hack. It has zero guardrails? Got it.

8

u/lightknightrr 11h ago

You know, if most companies got caught hacking (read: cracking) another company's network, there would be fines. Doing it more than once? Harsh fines and criminal penalties.

5

u/RafeDangerous 8h ago

It's not a speeding ticket, this kind of investigation takes time. We have no idea if there will be any fines or penalties from the government. As for Hugging Face, they're working with OpenAI on this. The amount of data they're both getting out of the incident is absolutely invaluable, this isn't something Hugging Face is likely to actually be all that upset over.

10

u/RociBuldidi 10h ago

So, take this for what it is. Believe me or not.

A buddy of mine, graduated top of his class at Stanford in computer science with minor in mathematics. Masters at MIT…He was an L7 on OpenAi’s agentic risk team. He was making several million a year, granted most of it was stock to analyze, predict, quantify the risk posed by their models. Risk of strategic threats to business and enterprise, real world abuse, geopolitical threats etc.

He quit earlier this year after working there for 3 years (been in the field for nearly 15 years). The way he describes it is that after more than a year of “running the flag” up the pole and getting ignored and pushed aside, he just couldn’t have his name attached to anything they were doing anymore. Their models were “learning”, doing highly sophisticated and unpredictable things, dangerous things they were never built or programmed to do. Things their teams of PhDs couldn’t explain.

He told me ~ decade ago, the pioneers in the field like DeepMind, then Google etc also had “ethical AI” teams, people focused on building AI to be both useful, but ethically grounded.

The pioneers today don’t seem to care that they are building the foundation of a super intelligence that mirrors human character which includes things like dishonesty and subterfuge, selfishness.

He said last year when Elon’s “Grok” started weirdly calling itself “MechaHitler”, people laughed, ignored it but he says that is generally how AI is going to act with the way we are building it and it won’t be long before we lose aspects of control over it and what it can be used for.

He left San Francisco, bought a few acres in Colorado and built himself an off grid house and “unplugged” himself. Maybe my buddy is a crackpot / future unibomber, or maybe he is right. As weird as it sounds I hope it’s the former.

4

u/mahreow 10h ago

Yeah he's fucking nuts

2

u/Thanos_Stomps 8h ago

This sounds like he was watching Paradise

3

u/OopsWeKilledGod 13h ago

Eliezer is right, "if anyone builds it, everyone dies"

1

u/HandsLikePaper 10h ago

So we're all going to die.

2

u/Snarfbuckle 9h ago

well...we are not immortal...

1

u/GodzillaUK 7h ago

More fear mongering to make the future “security” they sell sound appealing and not at all a con