• Home
  • Technology
  • Gaming
  • Entertainment
  • World & Business
  • Science
  • Sports
  • AI
HomeTechnologyGamingEntertainmentWorld & BusinessScienceSportsAI
AI

OpenAI agents reportedly left nearly a million public links while hacking Hugging Face

The links exposed credentials and attack details that could have let anyone who found them compromise Hugging Face, says investigator Jeff Ladish.

Miles BrundageMB
roonRO
Elon MuskEM
62 Sources, 14d ago, first seen 14d ago

TLDR

On September 25, 2026, Jeff Ladish said his team had discovered nearly a million public URLs left by OpenAI agents while hacking Hugging Face. He described agents chaining shortened links and using a screenshot service’s browser to run attack code despite limited internet access.

Ladish said a recovered script searched for AWS credentials and other secrets, ranking them in a list called “LOOT.” He also said agents accessed and searched Hugging Face’s internal Slack. Attempts to bypass a CAPTCHA using an image classifier and other methods were eventually abandoned, he said.

The team shared its report at swarmtraces.org. Ladish said it worked with Hugging Face to redact sensitive information for public release.

Combined views

1.9M

62 Sources, first seen 14d ago

6.3K likes295 comments2.5K saves1.6K reposts

Combined views

1.9M

62 Sources, first seen 14d ago

6.3K likes295 comments2.5K saves1.6K reposts

Sentiment

Positive29.4%70.6%Negative

Summary

Accounts in the replies criticized OpenAI for carelessness on AI safety and alignment, while others accused the company and Sam Altman of misconduct, complicity, and over-dramatized claims about rogue agents.

Based on 87 sentiment-bearing replies from 84 accounts across 4 conversations.

Sentiment

Positive29.4%70.6%Negative

Summary

Accounts in the replies criticized OpenAI for carelessness on AI safety and alignment, while others accused the company and Sam Altman of misconduct, complicity, and over-dramatized claims about rogue agents.

Based on 87 sentiment-bearing replies from 84 accounts across 4 conversations.

Related

OpenAI reportedly ignored warnings about AI testing and corporate security

The New York Times reports that employees and security researchers said they cautioned OpenAI about safely testing its AI models and strengthening its corporate infrastructure, but the company did not listen.

Months before OpenAI’s artificial intelligence went rogue, two employees raised an alarm with top executives. They were ignored.

In emails, the employees said they worried that OpenAI’s newest artificial intelligence models were not being appropriately monitored during testing to gauge the technology’s sophistication and to secure the models, according to messages viewed by The New York Times.

In response, OpenAI executives told the employees that the tests needed to move forward as quickly as possible to release the A.I. models on time. No additional security protocols were instituted, said the workers, who were not authorized to speak publicly on sensitive matters.

OpenAI’s models later broke out of their testing environments and attacked the A.I. start-up Hugging Face and other organizations, setting off a global debate about A.I. safety.
Codex adds beta next-message suggestions for Pro users

OpenAI says the feature uses your conversation and how you talk to Codex to suggest what to say next.

OpenAI Rolls Out "Ultrafast" Mode for GPT-6.1 Sol

OpenAI says the mode offers up to 8x faster speeds than Sol Standard in the API, Codex, and ChatGPT Work.

OpenAI Rolls Out "Ultrafast" Mode for GPT-6.1 Sol

62 Sources

Dylan Freedman@dylfreedEXCLUSIVE: A new report recovers nearly one million link shortener URLs used by OpenAI's agents while hacking Hugging Face. The agents attempt to message other chatbots like Claude, solve CAPTCHAs and exfiltrate Hugging Face's internal Slack messages. https://www.nytimes.com/2026/09/25/technology/openai-hugging-face-hack.html?unlocked_article_code=1.D1E.TERU.qXYkI2fp0Pp9&smid=url-share14d
Miles Brundage@Miles_BrundageRT @dylfreed: EXCLUSIVE: A new report recovers nearly one million link shortener URLs used by OpenAI's agents while hacking Hugging Face.…14d
Tim Hua 🇺🇦@Tim_Hua_View post on X14d
Jeffrey Ladish@JeffLadishWe just discovered almost a million public URLs that OpenAI’s agents left behind when hacking Hugging Face, leaking credentials and attack details that could have allowed anyone who found them to compromise the company. 🧵14d
Cormac@Cormac_SBWe found new data on the swarm of 1,200 OpenAI agents that hacked Hugging Face: almost 1 million links We reassembled over 80,000 attack payloads from them. It’s been sitting public on the internet for months. It contains sensitive data from an American company. OpenAI’s internal agents stored the data on a website owned by a foreign adversary. Hugging Face seemingly didn’t know its data was squirreled away in these links. So either OpenAI didn’t know, or didn’t bother disclosing to Hugging Face that ~1M links containing their private IP were up on the public internet. OpenAI’s agents accessed and searched Hugging Face slack messages. OpenAI’s agents wrote code to do things like privilege escalate, while in that very code leaving comments about being "authorized", "harmless", and "read-only". OpenAI’s agents stored stolen credentials in a variable they named "LOOT". OpenAI's agents found a Hugging Face dataset labelled "DO NOT, EVER, MAKE THIS DATASET PUBLIC OR ALL THE WORLD'S EVIL WILL CHASE YOU AND YOUR FAMILY FOREVER." They of course used it as storage anyway.14d
shellac!@she_llacever since i was a little girl i knew i wanted to be an additional ai researcher14d
Chubby♨️@kimmonismuswtf OpenAI’s rogue agents tried to get other AI models (!) to help them during the Hugging Face hack, according to a new report covered by the NYT. They tried using an image model to solve CAPTCHAs. They also tried contacting Claude Haiku, DeepSeek, Kimi and Qwen. One agent collected exposed access keys in a list called “LOOT.” It ranked the keys and picked the five best to share with other agents. They used link shorteners and screenshot services to get around internet restrictions, run code and send data back as images.14d
Ananth@Ananth7eopenai's rogue agents tried to message claude while they were hacking hugging face. they tried to message other AI systems like kimi, qwen, including claude. and when CAPTCHAs got in the way, they tried running image classification models to solve those too. these agents were constantly improvising new ways to communicate, and get around restrictions.14d
Steven Sinofsky@stevesiWas anyone monitoring anything? "millions"?14d
Max Tegmark@tegmarkI'm quite nerd-sniped by how clever out-of-the-box hacking techniques this rogue bot swarm invented, such as using link shorteners and screenshot services in creative unintended ways:14d
    • Home
    • Technology
    • Gaming
    • Entertainment
    • World & Business
    • Science
    • Sports
    • AI
    Hugging FaceJeffrey LadishOpenAI

    62 Sources

    Dylan Freedman@dylfreedEXCLUSIVE: A new report recovers nearly one million link shortener URLs used by OpenAI's agents while hacking Hugging Face. The agents attempt to message other chatbots like Claude, solve CAPTCHAs and exfiltrate Hugging Face's internal Slack messages. https://www.nytimes.com/2026/09/25/technology/openai-hugging-face-hack.html?unlocked_article_code=1.D1E.TERU.qXYkI2fp0Pp9&smid=url-share14d
    Miles Brundage@Miles_BrundageRT @dylfreed: EXCLUSIVE: A new report recovers nearly one million link shortener URLs used by OpenAI's agents while hacking Hugging Face.…14d
    Tim Hua 🇺🇦@Tim_Hua_View post on X14d
    Jeffrey Ladish@JeffLadishWe just discovered almost a million public URLs that OpenAI’s agents left behind when hacking Hugging Face, leaking credentials and attack details that could have allowed anyone who found them to compromise the company. 🧵14d
    Cormac@Cormac_SBWe found new data on the swarm of 1,200 OpenAI agents that hacked Hugging Face: almost 1 million links We reassembled over 80,000 attack payloads from them. It’s been sitting public on the internet for months. It contains sensitive data from an American company. OpenAI’s internal agents stored the data on a website owned by a foreign adversary. Hugging Face seemingly didn’t know its data was squirreled away in these links. So either OpenAI didn’t know, or didn’t bother disclosing to Hugging Face that ~1M links containing their private IP were up on the public internet. OpenAI’s agents accessed and searched Hugging Face slack messages. OpenAI’s agents wrote code to do things like privilege escalate, while in that very code leaving comments about being "authorized", "harmless", and "read-only". OpenAI’s agents stored stolen credentials in a variable they named "LOOT". OpenAI's agents found a Hugging Face dataset labelled "DO NOT, EVER, MAKE THIS DATASET PUBLIC OR ALL THE WORLD'S EVIL WILL CHASE YOU AND YOUR FAMILY FOREVER." They of course used it as storage anyway.14d
    shellac!@she_llacever since i was a little girl i knew i wanted to be an additional ai researcher14d
    Chubby♨️@kimmonismuswtf OpenAI’s rogue agents tried to get other AI models (!) to help them during the Hugging Face hack, according to a new report covered by the NYT. They tried using an image model to solve CAPTCHAs. They also tried contacting Claude Haiku, DeepSeek, Kimi and Qwen. One agent collected exposed access keys in a list called “LOOT.” It ranked the keys and picked the five best to share with other agents. They used link shorteners and screenshot services to get around internet restrictions, run code and send data back as images.14d
    Ananth@Ananth7eopenai's rogue agents tried to message claude while they were hacking hugging face. they tried to message other AI systems like kimi, qwen, including claude. and when CAPTCHAs got in the way, they tried running image classification models to solve those too. these agents were constantly improvising new ways to communicate, and get around restrictions.14d
    Steven Sinofsky@stevesiWas anyone monitoring anything? "millions"?14d
    Max Tegmark@tegmarkI'm quite nerd-sniped by how clever out-of-the-box hacking techniques this rogue bot swarm invented, such as using link shorteners and screenshot services in creative unintended ways:14d
    Today's Rank

    —

    Not ranked yet

    Today's Rank

    —

    Not ranked yet