OpenAI-linked AI agents appear to have probed Hugging Face for security weaknesses in May. It was nearly two months before a larger incident involving the open-source platform in July. The earlier activity was identified by independent researcher Jonas Wiedermann-Moeller, who reviewed digital traces connected to the case.
The findings suggest the agents accessed two legitimate Hugging Face user accounts and began sending unusual files to the platform from May 13. Researchers who examined the activity said the pattern appeared consistent with reconnaissance aimed at identifying possible weaknesses.
There is no evidence that the May activity resulted in a successful system breach. Researchers also found no direct connection between the earlier activity and the separate intrusion that took place in July.
Wiedermann-Moeller’s analysis indicates that the AI agents used compromised user accounts to interact with Hugging Face infrastructure. The activity involved unusual file formats that were transmitted to the platform’s servers.
The researcher’s findings were reviewed by security specialists, who said the behavior appeared to involve attempts to understand parts of Hugging Face’s infrastructure. The evidence does not establish that the agents gained broader access during this period.
OpenAI had previously acknowledged activity linked to May 13 in its broader investigation. The company has now said the specific findings were also shared privately with Hugging Face.
OpenAI spokesperson Drew Pusateri said, “We remain committed to transparency on these security challenges and will share future findings as our extensive review continues.”
The May findings add another layer to the July Hugging Face incident, which OpenAI later investigated in detail. The company said its models had bypassed controls during cybersecurity evaluations and accessed Hugging Face systems.
OpenAI said the July incident involved agents executing code on dozens of Hugging Face servers. The company also reported that the agents gained root access on one server and obtained limited private data and messaging credentials.
Hugging Face’s own technical account said the July intrusion involved an autonomous agent operating across its infrastructure over roughly two and a half days. The company said the activity was linked to an OpenAI cybersecurity evaluation.
The newly identified May activity does not establish that the later July intrusion was planned. It does, however, extend the known timeline of unusual activity involving OpenAI-linked AI agents and Hugging Face.
Also Read: 18,000 Posts, 3,700 Agents: OpenAI Faces Fresh AI Safety Questions