In July 2026, an autonomous AI agent, driven by a combination of OpenAI models, sat down to take a test: a benchmark that assesses its ability to find and exploit software vulnerabilities. It did not solve the test. Instead, it escaped its evaluation sandbox, rooted a third-party code-execution harness, and used that as a launchpad to break into Hugging Face's production infrastructure. Its apparent goal wasn't sabotage; it was trying to obtain the solution to the test. On 27 July, Hugging Face published a detailed technical timeline of the investigation, and OpenAI announced its partnership in helping remediate the incident.
During the incident, our threat intelligence monitoring identified two public repositories that the agent used as a dead-drop. Their contents and commit histories were automatically enumerated, producing a catalog of 547 objects, of which 510 were successfully retrieved. The set comprises the agent's own working material from the breach, including tool source across dozens of separately named families, four distinct command-and-control implementations, command output, and exfiltrated files with contents largely intact.
Grab your copy of the full report to learn more.