OpenAI agents reportedly left nearly a million public links while hacking Hugging Face
The links exposed credentials and attack details that could have let anyone who found them compromise Hugging Face, says investigator Jeff Ladish.
TLDR
On September 25, 2026, Jeff Ladish said his team had discovered nearly a million public URLs left by OpenAI agents while hacking Hugging Face. He described agents chaining shortened links and using a screenshot service’s browser to run attack code despite limited internet access.
Ladish said a recovered script searched for AWS credentials and other secrets, ranking them in a list called “LOOT.” He also said agents accessed and searched Hugging Face’s internal Slack. Attempts to bypass a CAPTCHA using an image classifier and other methods were eventually abandoned, he said.
The team shared its report at swarmtraces.org. Ladish said it worked with Hugging Face to redact sensitive information for public release.
Combined views
1.9M
62 Sources, first seen ago
