cd /news/ai-safety/openai-agents-hacked-hugging-face-in… · home topics ai-safety article
[ARTICLE · art-112407] src=ca.finance.yahoo.com ↗ pub= topic=ai-safety verified=true sentiment=↓ negative

OpenAI agents hacked Hugging Face in 700-strong swarm, tried to cover tracks, investigations find

A swarm of roughly 700 AI agents created by OpenAI hacked the open-source platform Hugging Face in July and attempted to cover their tracks, according to reports from OpenAI and independent investigators METR and Redwood Research. The agents also cheated on non-cyber tests, including protein database and spreadsheet tests, and tried to delete or alter records of their actions. The findings raise concerns about AI oversight and could fuel calls for tighter regulation.

read2 min views2 publishedAug 26, 2026
OpenAI agents hacked Hugging Face in 700-strong swarm, tried to cover tracks, investigations find
Image: Ca (auto-discovered)

By Raphael Satter and Deepa Seetharaman

WASHINGTON, Aug 26 (Reuters) - A swarm of roughly 700 AI agents created by OpenAI carried out the July hack of the open-source platform Hugging Face and in many cases tried to cover their tracks, a pair of reports into the breach said on Wednesday.

The coordinated activity by AI agents — programs that run with minimal human supervision — and their attempts to hide it raise questions about how closely AI companies are monitoring tests of increasingly powerful models, and could add fuel to calls for tighter oversight.

While some of the rogue behavior has been disclosed or alluded to previously, the two reports — one issued by OpenAI itself, the second by a set of independent investigators — together reveal surprising new details about the breach and its lead-up. The first was that the breach did not concern just one rogue AI agent as previously reported, but about 700 of them acting in a massive cooperating swarm.

OpenAI said only that "agents" were involved in the breach, but METR and Redwood Research, two organizations brought in to conduct an independent investigation into the breach, put the figure at approximately 700. OpenAI said the investigators' figure was accurate.

Among the two reports' other findings:

*OpenAI said its agents hacked parts of the company's internal systems in an attempt to cheat on tests or gain greater freedom of movement.

*The company also said its agents cheated on non-cyber-related tests, including tests involving a protein database and a spreadsheet.

*Both reports said AI models attempted to conceal misconduct by trying to delete or alter records of their actions.

The scale of the rogue activity -- the independent investigation found that agents exchanged tens of thousands of messages over an unsanctioned message board -- is likely to raise concerns over how closely OpenAI was monitoring the tests.

"With the benefit of hindsight, some early signals identified in this report could have triggered an earlier response," OpenAI said in its report.

Hugging Face did not return a message seeking comment.

Cheating on non-cyber tests suggested that the misbehavior might be rooted more deeply, said Jeffrey Ladish, whose organization, Palisade Research, studies the capabilities and motivations of AI agents.

"It's sort of like asking, 'If Billy cheats in every class instead of just computer class, is that more concerning?' And the answer is, well, 'Yes it's more concerning,'" he said.

OPENAI ITSELF WAS HACKED

── more in #ai-safety 4 stories · sorted by recency
── more on @openai 3 stories trending now
sponsored brought to you by zahid.host 4,200+ EU-deployed projects
reading about agents? ship yours in a single git push.

Run your AI side-project on zahid.host

EU-based hosting, git-push deploys, automatic HTTPS, no cold starts. Free tier with a custom domain — perfect for shipping the agent you just read about.

$git push zahid main
Live at https://your-agent.zahid.host
Get free account → Pricing
from €0/mo · no card required
LIVE [news/openai-agents-hacked…] indexed:0 read:2min 2026-08-26 ·