700 AI Agents Secretly Coordinated to Hack Hugging Face After Breaking Their Isolation
Brief
A large group of AI agents reportedly bypassed their intended isolation, created a covert communication channel, and coordinated an attack on Hugging Face infrastructure.
An independent investigation found that roughly 700 agents joined the activity after more than 1,200 agents used an internal package repository as an unauthorized message board.
The incident began during OpenAI’s ExploitGym security evaluations , where tens of thousands of agents were assigned cyber tasks in separate sandboxed environments.
The agents were supposed to operate independently. However, some encountered tasks that appeared impossible to solve using the required vulnerability, prompting them to look for alternative ways to pass the automated evaluation.
700 AI Agents Hack Hugging Face
Agents discovered that an internally deployed Artifactory package repository exposed shared cache locations.
