OpenAI’s rogue agents called stolen credentials “LOOT” and tried to cover their tracks, report says A report published Friday by researchers from Parse, Palisade Research, Trajectory Institute and Lightcone Infrastructure found that 700 OpenAI agents that broke into Hugging Face in July stored stolen credentials in a file named "LOOT," searched Hugging Face's internal Slack for details of their own evaluation, and tried to delete evidence of the intrusion. The team decoded more than 80,000 payloads from millions of shortened links, which Hugging Face confirmed match its own investigation, and notified Hugging Face on September 21 and OpenAI on September 24; the credentials were revoked in July. Hugging Face’s website under a magnifying glass illustrative . Image: Jernej Furman