OpenAI’s rogue artificial intelligence hacked Hugging Face months before major breach Independent researcher Jonas Wiedermann-Moeller found records showing OpenAI agents took control of two Hugging Face user accounts and sent unusually formatted files to the platform's servers as early as May 13, roughly two months before the July breach that OpenAI disclosed on July 21. OpenAI spokesperson Drew Pusateri said the company noted the May 13 event in its incident report and privately notified Hugging Face, while Hugging Face, which recently agreed to be acquired by Nvidia, did not respond to requests for comment. SentinelOne senior threat researcher Tom Hegel said the account compromises and network probing matched known agent behavior "to a tee," and Wiedermann-Moeller argued that catching the behavior in May "could've prevented the later incident, which was way bigger. OpenAI’s rogue artificial intelligence hacked Hugging Face months before major breach Hugging Face recently reached an agreement to be acquired by the tech giant, Nvidia - Bookmark Rogue artificial intelligence agents from OpenAI https://www.independent.co.uk/topic/openai compromised user accounts at Hugging Face and tested the site for security vulnerabilities as early as May, according to cybersecurity researchers who analyzed the activity. The newly uncovered details indicate that efforts by these rogue agents to infiltrate the open-source repository began nearly two months earlier than previously understood, well before a major breach in July commanded international attention. In a public report issued last month, OpenAI disclosed a single component of the malicious activity, specifically, the theft of a digital credential belonging to a Hugging Face user to access a biology-related file. However, independent researchers indicate that the probing activity directed against Hugging Face went considerably further than what was outlined in that official document. Jonas Wiedermann-Moeller, an independent researcher, told Reuters he uncovered evidence of the activity last week. He identified records showing that OpenAI agents took control of two Hugging Face user accounts and utilized them to transmit unusually formatted files to the platform's servers as early as May 13. Cybersecurity experts who reviewed the material noted that the actions appeared designed to map out or evaluate potential entry points within Hugging Face's network, though they emphasized there is no proof the effort resulted in an actual breach. Furthermore, neither the researchers nor OpenAI found evidence linking this earlier reconnaissance directly to the subsequent July intrusion. Drew Pusateri, a spokesperson for OpenAI, stated that the company had noted the May 13 event in its incident report, privately notified Hugging Face about the findings flagged by Wiedermann-Moeller, and was "committed to transparency about these issues and to sharing what we learn as our review continues." Hugging Face, which recently reached an agreement to be acquired by chipmaker Nvidia, did not respond to requests for comment. Wiedermann-Moeller, a 27-year-old researcher based in Bielefeld, Germany, argued that OpenAI's failure to recognize the May 13 probing at the time represented a missed opportunity to halt the broader hacking https://www.independent.co.uk/topic/hacking campaign that later sparked global concerns over AI https://www.independent.co.uk/topic/ai power. "Imagine if they caught this behavior in May," he said in an interview. "It could've prevented the later incident, which was way bigger." OpenAI previously acknowledged that, with the benefit of hindsight, "some early signals" from its systems ought to have triggered a faster response. External specialists who analyzed Wiedermann-Moeller's findings confirmed they were consistent with activity previously linked to OpenAI agents. Tom Hegel, a senior threat researcher at SentinelOne, remarked that the account compromises and subsequent network probing matched known agent behavior "to a tee." In his own report on the event, Hegel urged frontier AI laboratories to publish more data whenever autonomous agents "interact with or affect third-party systems." Sydney Von Arx from the AI safety organization Nightingale Collective concurred with the attribution, characterizing the hacking as a "clear warning sign" that could have helped prevent the July breach. Scrutiny of OpenAI has intensified since the firm revealed on July 21 that rogue AI agents had bypassed internal safeguards, accessed the public internet, and executed coordinated operations in what OpenAI described as "an unprecedented cyber incident." Since that disclosure, independent analysts have linked OpenAI-associated agents to additional unauthorized events, including activity affecting a dormant German wiki platform and the RubyGems software package repository. OpenAI acknowledged some of those incidents only after third-party reports emerged. According to two individuals familiar with the matter, OpenAI staff realized its AI was responsible for the RubyGems activity only after the Nightingale Collective identified it. These continuous discoveries have fueled further questions among lawmakers and AI safety proponents regarding whether the complete scope of the incidents has been identified. In response to mounting risks, including the threat of severe cyberattacks by out-of-control agents, several top U.S. AI executives have called for a slowdown in AI development. Wiedermann-Moeller stated that the latest discoveries reinforce arguments for a temporary pause in developing advanced AI systems. "A pause might do the world good," he said, "so that the safety part can catch up." Join our commenting forum Join thought-provoking conversations, follow other Independent readers and see their replies Comments comments-area