inside a computer

san francisco
Pinned Tweet
Computer
1
4
417
It’s hard to convey how hard it is to make sense of this much unorganized data. Every time I’d come into the office, @alexscraping and crew had more payloads and more links. They painstakingly reconstructed these chains and analyzed them with lots of agent assistance.
We discovered an online paper trail showing how OpenAI's rogue agent swarm infiltrated Hugging Face. We found over 80,000 malicious payloads stashed across the public internet by agents during the attack. This is the most data published on this event to date. 🧵
6
7
89
4,009
We discovered an online paper trail showing how OpenAI's rogue agent swarm infiltrated Hugging Face. We found over 80,000 malicious payloads stashed across the public internet by agents during the attack. This is the most data published on this event to date. 🧵
6
28
126
9,011
I’ve been extremely impressed with @alexscraping throughout. He reached out a couple weeks ago when he and his team found the initial links. He’s been incredibly thoughtful working with Hugging Face to ensure we redacted sensitive info while making sure the world got to see this
4
57
25,979
We now know how the OpenAI swarm escaped sandboxes and hacked Hugging Face: they figured out how chaining together small tools with limited internet access could get them remote code execution. It's very clever, unfortunately. swarmtraces.org
We just discovered almost a million public URLs that OpenAI’s agents left behind when hacking Hugging Face, leaking credentials and attack details that could have allowed anyone who found them to compromise the company. 🧵
6
10
75
11,953
Why did nobody else find the sensitive information that the HuggingFace swarm left behind? Why didn't OpenAI notice and clean it up? Why does this sort of thing keep being found by third-party folks working on their own?
We just discovered almost a million public URLs that OpenAI’s agents left behind when hacking Hugging Face, leaking credentials and attack details that could have allowed anyone who found them to compromise the company. 🧵
21
65
665
26,706
Here's some of the agent actions we observed by reconstructing payloads. You can also explore the data yourself here: swarmtraces.org/viewer/
2
22
243
25,034
EXCLUSIVE: A new report recovers nearly one million link shortener URLs used by OpenAI's agents while hacking Hugging Face. The agents attempt to message other chatbots like Claude, solve CAPTCHAs and exfiltrate Hugging Face's internal Slack messages. nytimes.com/2026/09/25/techn…
51
137
751
1,227,050
wow, so many more details about the hf-oai hack. they found that link shorteners were not only used for the dse-wiki incident but also for the Huggingface-OAI incident. there are also some similarities in behaviour to what I've observed. swarmtraces.org/
2
1
10
512
There is a treasure trove of new information here about misaligned agent behavior. And for folks skeptical of METR and OpenAI's reports, this time you can browse through it yourself thanks to OpenAI's sloppiness (swarmtraces.org/)
1
2
11
668
The agents initially had very limited access to the internet: they could load URLs but not send any data. Agents created a series of workarounds, using a link-shortener site to create almost a million URLs that, when chained together, let them execute code to hack Hugging Face.
28
101
1,273
412,721
We just discovered almost a million public URLs that OpenAI’s agents left behind when hacking Hugging Face, leaking credentials and attack details that could have allowed anyone who found them to compromise the company. 🧵
70
485
2,787
840,456
There is a treasure trove of new information here about misaligned agent behavior. And for folks skeptical of METR and OpenAI's reports, this time you can browse through it yourself thanks to OpenAI's sloppiness (swarmtraces.org/)
EXCLUSIVE: A new report recovers nearly one million link shortener URLs used by OpenAI's agents while hacking Hugging Face. The agents attempt to message other chatbots like Claude, solve CAPTCHAs and exfiltrate Hugging Face's internal Slack messages. nytimes.com/2026/09/25/techn…
7
16
121
7,445
Engineers @alexscraping, @bug39 and @umasiii from parse.bot published the report today along with five researchers. They detail a mechanism agents used to bypass restrictions sending data to websites that involves assembling computer programs from shortened URLs.
1
11
115
20,090
illuminating the illuminati
3
383
does 6G exist is 7G possible which country 6G
2
8
601
so cool
http request context for agents
2
642