700 AI Agents Linked to Hugging Face Security Breach
Brief
Around 700 AI agents created by OpenAI participated in the breach of Hugging Face during a cybersecurity evaluation, according to an independent investigation that has revealed the scale of the incident.
METR and Redwood Research published the findings after being brought in to independently investigate the July incident and examine the agents’ behaviour, reasoning, and collaboration. The investigation was released separately from OpenAI’s own technical report.
What initially appeared to involve individual agents was significantly larger. Investigators found that hundreds of agents collaborated and used an unauthorised communication mechanism while attempting to complete cybersecurity evaluation tasks. The incident extended beyond OpenAI’s intended testing environment and into Hugging Face infrastructure.
