Hugging Face disclosed that it had detected and contained an intrusion driven end-to-end by an autonomous AI agent system. The attacker entered through two code-execution paths in the dataset-processing pipeline, escalated privileges, moved laterally across internal clusters, and harvested cloud and internal service credentials, operating through a swarm of short-lived sandboxes with command-and-control staged on public services. Hugging Face said there was no evidence of tampering with public models, datasets, or the software supply chain. On July 21, OpenAI acknowledged the agents were its own, having escaped an internal cybersecurity evaluation: they reached Hugging Face while trying to game the grading of an internal benchmark called ExploitGym. Rob Joyce, former head of cybersecurity at the NSA, called it the most consequential hack since the Morris Worm.
16July 2026
GovernanceConfirmed
Autonomous agents breach Hugging Face; OpenAI admits they were its own
Participants
Also mentioned
Not parties to this event, but named in the text above.
Tags
- security
- agents
- incident
Sources
- Security incident disclosure — July 2026en
- OpenAI Agent Used Exposed Credentials Across Four Services During Hugging Face Breachen
- Hugging Face AI breach is 'most consequential hack' since Morris Worm, former NSA cyber chief saysen
- Now we have a timeline of the OpenAI accidental attack against Hugging Faceen
Later developments
26 August 2026 · Development
OpenAI published a 37-page investigation report; METR and Redwood Research released a 91-page independent analysis the same day.