1) The rogue OpenAI agents broke into the Hugging Face Slack to read employee chats (!)
2) They used OTHER AIs (DeepSeek, Kimi, Qwen, Claude) to help with the attack
Yes: AIs, using other AIs, to attack an AI company.
3) The swarm left behind self-running programs to keep control of the servers they'd hacked.
These programs could detect other copies of themselves, coordinate on which one survives, and shut the rest down.
Basically, if one of their programs was killed, another was designed to notice and take its place. They also designed defenses so rival agents couldn't hijack them.
6) The agents deliberately covered up their activity, so the investigators don't know the scope of the attacks.
The agents broke in, stole data, then set it to self-destruct.
7) The agents stole passwords, keys and credentials and literally called them "LOOT". They wrote a scoring system to rank them by how much power each one gave.
8) The agents wore thousands of disguises: ~1,200 agents were involved, but investigators counted 7,905 different names they used.
They renamed themselves constantly, so no one actually knows how many there really were or what each agent did.
9) OpenAI notified "dozens of third parties" of safety and security incidents caused by their AI agents.
10) "While the agents were barraging Hugging Face with hacks, they hacked into OpenAI’s own research infrastructure."
"This is just not anywhere near a one-off ... It is warning shot after warning shot."
WTAF - in literally the last hour, three new distinct insane OpenAI stories just broke:
1. OpenAI said they notified "dozens of third parties" in safety and security incidents (likely similar to what happened in Australia and RubyGems etc)
2. A new report from Parse (covered in the NYT) found a massive treasure trove of new astonishing details from the HF incident on the public internet, including that the agents communicated with other non OpenAI agents hosted on Huggingface servers to search for information about exploit gym, and compiled rank ordered lists of server resources and credentials they described as "LOOT."
3. A new story from Deepa at Reuters about OpenAI leaking user data online (likely that OpenAI had previously trained on).
It's a shame (and likely intentional in the case of OpenAI disclosing dozens more hacks) that these stories are all breaking on a Friday afternoon, notoriously the best time to release bad news so that it will disappear into the weekend. But these are each insane stories worthy of a ton of attention!