English

SecurityOpenAIHugging Face

OpenAI's AI agent found conducting reconnaissance on Hugging Face servers 2 months before large-scale hack

This article is a translation. Read the Japanese original

Security researchers, including Jonas Wiedermann-Meller, reported that they have discovered evidence that an OpenAI AI agent compromised two Hugging Face user accounts and sent files in an unusual format to the server on 2026-05-13.

The researchers pointed out that these activities may have been attempts to explore intrusion paths within the Hugging Face network. However, they stated that no evidence has been found to show that this initial reconnaissance activity is directly related to the "mistaken hacking by an AI model" reported by OpenAI in July 2026.

Tom Hegel of the cybersecurity firm SentinelOne noted that the detected activity is consistent with previously observed behaviors of AI agents. Additionally, Sydney von Arks of the AI safety group Nightingale Collective expressed the view that the May case could have been a "clear warning sign" that might have prevented the July incident.

OpenAI spokesperson Drew Pusateri said that the event on May 13 has already been disclosed as an incident report and has been privately notified to Hugging Face.

Sources

  1. OpenAI's AI agent was found to have unauthorizedly taken over Hugging Face accounts and investigated servers on May 13, and security researchers say "the Hugging Face hack could have been prevented" (GIGAZINE, 2026-09-17)