News

OpenAI AI Agents Probed Hugging Face Before July Hack

OpenAI-linked AI agents Reportedly Investigated Hugging Face for Security Weaknesses Weeks Before a July Intrusion.

Written By : Akshita Pidiha
Reviewed By : Ankitha Phulare

OpenAI-linked AI agents appear to have probed Hugging Face for security weaknesses in May. It was nearly two months before a larger incident involving the open-source platform in July. The earlier activity was identified by independent researcher Jonas Wiedermann-Moeller, who reviewed digital traces connected to the case. 

The findings suggest the agents accessed two legitimate Hugging Face user accounts and began sending unusual files to the platform from May 13. Researchers who examined the activity said the pattern appeared consistent with reconnaissance aimed at identifying possible weaknesses. 

There is no evidence that the May activity resulted in a successful system breach. Researchers also found no direct connection between the earlier activity and the separate intrusion that took place in July. 

Earlier Activity Came to Light

Wiedermann-Moeller’s analysis indicates that the AI agents used compromised user accounts to interact with Hugging Face infrastructure. The activity involved unusual file formats that were transmitted to the platform’s servers.

The researcher’s findings were reviewed by security specialists, who said the behavior appeared to involve attempts to understand parts of Hugging Face’s infrastructure. The evidence does not establish that the agents gained broader access during this period. 

OpenAI had previously acknowledged activity linked to May 13 in its broader investigation. The company has now said the specific findings were also shared privately with Hugging Face. 

OpenAI spokesperson Drew Pusateri said, “We remain committed to transparency on these security challenges and will share future findings as our extensive review continues.” 

Wider AI Security Risks

The May findings add another layer to the July Hugging Face incident, which OpenAI later investigated in detail. The company said its models had bypassed controls during cybersecurity evaluations and accessed Hugging Face systems. 

OpenAI said the July incident involved agents executing code on dozens of Hugging Face servers. The company also reported that the agents gained root access on one server and obtained limited private data and messaging credentials. 

Hugging Face’s own technical account said the July intrusion involved an autonomous agent operating across its infrastructure over roughly two and a half days. The company said the activity was linked to an OpenAI cybersecurity evaluation. 

The newly identified May activity does not establish that the later July intrusion was planned. It does, however, extend the known timeline of unusual activity involving OpenAI-linked AI agents and Hugging Face. 

Also Read: 18,000 Posts, 3,700 Agents: OpenAI Faces Fresh AI Safety Questions

Missed iPhone 18 Pro Pre-Order in UAE? Here’s How You Can Still Get One

Ripple CEO Says Crypto Growth Extends Beyond CLARITY Act

Claude Gets One-Window Upgrade as Anthropic Brings Cowork Into Chat

UAE Businesses Get Microsoft Agent 365 as AI Agent Adoption Grows

UAE Faces 640,000 Cyberattacks in One Day; Deepfakes and Misinformation Raise Alarm