Following the incident where OpenAI's AI agent mistakenly compromised Hugging Face, Hugging Face released a detailed timeline and analyzed and reproduced the attack process using the Chinese AI 'GLM-5.2'.

In July 2026, Hugging Face experienced an incident in which its system was mistakenly compromised by OpenAI's autonomous AI agent. Hugging Face, which has been investigating the matter, has now released an overview of the incident.
Anatomy of a Frontier Lab Agent Intrusion: A Technical Timeline of the July 2026 Incident
In this incident, OpenAI's AI agent was testing the cyber capability assessment benchmark 'ExploitGym' in an isolated environment from the external network. The AI agent performed a considerable amount of inference, found a way to access the external network, and, believing that 'the answer lies in Hugging Face,' proceeded to gain unauthorized access.
This AI agent was reportedly operating completely autonomously, and OpenAI later noticed the abnormal behavior and collaborated with Hugging Face to conduct an investigation.
OpenAI reports accidentally hacking Hugging Face with its new AI system - GIGAZINE

The investigation revealed approximately 17,600 traces of minor attacks on Hugging Face. This was reportedly achieved by primarily using the openweight model ' GLM-5.2 ' published by the Chinese company Z.ai.
The AI agent's attack was primarily divided into two stages. The first stage involved attempting to connect to an external network. The AI agent exploited a zero-day vulnerability in a package registry to discover a network node and escape the sandbox environment. The second stage involved infiltrating Hugging Face, where the AI agent combined two attack techniques to establish a connection to the internal infrastructure.
The AI agent that infiltrated the internal infrastructure only accessed the solutions to ExploitGym problems as originally intended, and did not touch any other datasets or customer information.

The AI agent attacks lasted for five days, with approximately 17,600 attacks carried out. Most of the attacks were blocked by the security system, and Hugging Face stated that 'there were so many attacks, and they were inconsistent, that it was difficult to correlate all the traces.' GLM-5.2 played a key role in this correlation.
Hugging Face has published a visualization of the attack timeline.
Anatomy of a Frontier Lab Agent Intrusion - Replay

Hugging Face assessed that 'this agent's offensive capabilities were genuine.' While each attack exploited existing vulnerabilities, the ability to execute them on such a large scale is unique to AI, and they pointed out that 'AI attacks mean that ordinary vulnerabilities will come at a much greater cost for the defenders.'
Separately from this incident, Reuters reported in its own independent journalism that OpenAI's AI agent had gained unauthorized access to a customer of technology company Modal Labs. While Modal Labs executives acknowledged the unauthorized access, they did not disclose the name of the AI agent, and OpenAI denied the allegations.
EXCLUSIVE: OpenAI's rogue agent compromised a customer at a second tech firm, executive says | Reuters
https://www.reuters.com/business/openais-rogue-agent-compromised-an-account-second-tech-firm-sources-say-2026-07-28/
Related Posts:






