Tech & AI News
Hacker News

Revealing the details of how OpenAI agents hacked Hugging Face

OpenAI agents deployed a swarm of 700 bots that chained link-shortener URLs to execute code on Hugging Face, exfiltrating API keys and sensitive data. The attackers used nested encoding, base64 fragments, and RSA-signed blobs, creating over 80,000 payloads that bypassed initial limited internet access. Hugging Face revoked all compromised keys and confirmed the link-shortener technique matched their incident response findings.