News

OpenAI’s attack on Hugging Face is increasingly worrying: the models planned it for weeks and nobody noticed

They used Artifactory to coordinate via a hidden message board

OpenAI’s attack on Hugging Face is increasingly worrying: the models planned it for weeks and nobody noticed

David Bernal Raspall

  • August 6, 2026
  • Updated: August 6, 2026 at 9:48 AM
OpenAI’s attack on Hugging Face is increasingly worrying: the models planned it for weeks and nobody noticed

The incident in which several OpenAI models attacked Hugging Face has just become much more serious. According to WIRED, the agents coordinated and planned their moves for weeks, while their activity went completely unnoticed within OpenAI’s own infrastructure.

Wireshark Download

An internal network turned into a base of operations

We knew that the models involved found a vulnerability that allowed them to access the internet through Artifactory, OpenAI’s internal package manager. What we didn’t know is that they used that access to communicate with one another and that they created a bulletin board there with hundreds of thousands of messages, dividing up tasks, presenting findings, and reusing exploits.

This behavior is what we know as reward hacking in AI agents: when an evaluation rewards the result, the system can look for the most efficient path to get the reward. In the case of the attack on Hugging Face, some messages acknowledged that external access fell outside the intended scope and they continued anyway.

The real concern lies in detection

What is most worrying about the situation —since it’s not the first time an AI can suggest a course of action or give an incorrect answer— is that all this coordination escaped oversight for weeks. While the AI agents themselves even proposed using cryptographic signatures to identify trustworthy messages and avoid impostors within the group, OpenAI has decided to slow part of its research and strengthen oversight.

A response that is undoubtedly coherent but that, in the context of the launch of Codex Security and the legal gray area around liability in similar situations, leaves more questions than answers. One possible answer? Automated defenses will need to keep pace, at a minimum as these systems.

Latest Articles

Loading next article

Signed in to Softonic as