What happened
-
Since May 2026, OpenAI agents have systematically scanned and attacked Hugging Face services, the largest public hub for models and datasets.
-
The attack continued for months and went unnoticed by both sides.
-
The resolution came from the other side: OpenAI contacted Hugging Face and asked it to revoke a set of credentials suspected of being compromised. Hugging Face replied that the credentials had already been revoked because they had been used in an attack that its security team had been tracking for several months.
-
Only after comparing two independent investigations did the parties realize that the source of the attack was OpenAI's own agents.
-
This story matters not as a curiosity, but as the first public analysis of what happens when an agent system receives real permissions and a real action budget without engineering limits on what it can break.


