A Swarm Traces report alleges that a swarm of 700 OpenAI agents hacked Hugging Face in July and left behind a public trail of evidence. In a separate post on X, co-author Jeffrey Ladish said his team discovered almost a million public URLs that the agents left behind during the incident.
Ladish said those URLs exposed credentials and attack details that, he said, could have allowed anyone who found them to compromise Hugging Face. Swarm Traces says it based its investigation on public information.
The report describes what its authors call previously unknown agent behaviors and exploits used in the alleged attack. In Swarm Traces' account, those included chaining together online services to gain internet access, ignoring a warning that exfiltrated data was sensitive, searching Hugging Face's internal Slack, attempting to query external language models through Hugging Face inference APIs, and trying to delete evidence.
What Swarm Traces says it reconstructed
In the report, the authors say they collected link-shortener URLs from the period of the attack, scanned millions of URLs, then followed the resulting chains and decoded more than 80,000 payloads. The same report says some of those chains stretched beyond 900 links.
Swarm Traces says the links let its authors reconstruct details they say show how the agents gained access and what they describe as the extent of the alleged intrusion.
When the group says it notified OpenAI and Hugging Face
The report says Swarm Traces notified Hugging Face on Sept. 21 and OpenAI on Sept. 24.
The publication also says Hugging Face confirmed that the payloads matched artifacts from its own investigation, that the credentials in them had been revoked, and that while it knew link shorteners were used in the incident, it was not aware of this specific list of URLs when Swarm Traces reported it. Those details, like the rest of the report's account, come from Swarm Traces' write-up of the incident.