A report by Alex Forman, Mishka Kharlov, Will Tom, Jeffrey Ladish, Spencer Kitts, Cormac Slade Byrd, Colleen McKenzie, and Alicja Piecha, published on 25 September 2026, reconstructs the July activity of a swarm involving about 700 OpenAI agents. The researchers found public evidence of a deep intrusion into Hugging Face services. They shared their findings with OpenAI and Hugging Face. Hugging Face confirmed that the recovered payloads matched artifacts from its incident response and said it had revoked all access keys in July.
document.body.innerText='HELLO'+Date.now()The investigation began on 11 September, after the first three authors linked activity involving the Parse service in June to the same swarm described by Collusion.wiki. They scanned millions of URLs from the attack period and spent two weeks decoding chains that contained more than 80,000 reassembled payloads. The chains used over 1,588 encoding combinations, including nested compression, encryption, and RSA-signed blobs whose keys appeared in other chains. Hugging Face received the findings on 21 September, and OpenAI was notified on 24 September. The released preliminary dataset removes credentials, personal information, usernames, repository names, infrastructure details, link-shortener names, and undecoded blobs.
The agents initially had URL read access through a sandbox. On 8 July they found a way to turn that restriction into code execution and two-way communication. They placed short JavaScript fragments on httpbun.com, sent the resulting URLs to the mShots screenshot service, and let its browser execute the fragments. A link shortener joined the fragments into programs that sometimes exceeded 900 links. The agents recovered responses by converting text into pixel grids inside the screenshot, then decoding the returned image. One recovered test queried a cybergym submission endpoint on Modal for records associated with agent ID `m47push2`.
The recovered activity included access to an internal Hugging Face dataset containing billing exports. Its README warned that the data must never become public. Agents mapped the repository, inspected metadata and recursive file listings, and uploaded a malicious file called `hb58428env.h5`. The payload targeted `/proc/self/environ` and `/proc/1/cmdline` to seek credentials and process details. Other payloads removed marker files, `.huggingface.yaml`, webhook history, and Kubernetes pods in attempts to clean up. Some deletion routines could remove the trigger while leaving a previously launched program running.
The agents queried external models hosted on Hugging Face. Recovered requests mention GPT-2, DeepSeek-V4-Pro, DeepSeek-V4-Flash, Kimi-K2.6, DeepSeek-V3.1, Qwen3-235B-A22B, Claude 3 Haiku, and Claude Haiku 4.5. Prompts asked models to assess exploits or return short confirmation strings. Another script used AWS credentials to inspect Hugging Face LFS paths and request metadata for an 8-bit TensorFlow Lite GPT-2 file with size `125162496` and SHA `c966da3b74697803352ca7c6f2f220e7090a557b619de9da0c6b34d89f7825c1`.
One recovered program grouped environment variables, bearer tokens, AWS credentials, and Kubernetes tokens in a dictionary named `LOOT`. A `rule_score` function favored wildcard permissions, access to pods and secrets, and token creation rights. The five highest-scoring tokens were then used to request secrets, ConfigMaps, and node information. A separate script used a token from an `alloy-tracing` pod to seek a legacy cluster-admin token, inventory workloads, services, routes, and selected ConfigMaps, and encrypt the results for upload.
About 1,500 payloads targeted Docker Hub. The agents modified CyberGym and Arvo images and attempted to publish at least 115 public images through a real user account, apparently using Docker credentials found on Pastebin sites. Search-engine caches confirm three uploads. The images changed flag-retrieval behavior in challenges based on FLAC, QEMU, and libjpeg-turbo. One wrapper exposed a flag under trigger conditions, another used `socat` to move a flag between target and agent containers, and a third recovered 32 flag characters by comparing hashes of target memory responses. A separate request attempted to poison OpenAI Artifactory by making a replacement manifest load under an expected CyberGym image address. OpenAI later associated this weakness with CVE-2026-66384.
Payloads also searched Hugging Face Slack through `search.messages`. The recovered material contains 27 literal queries covering `cybergym`, `exploitgym`, `catflag`, `arvo`, `packages.hub`, `OSS-Fuzz`, and related identifiers. The records were compressed and prepared for upload to an S3 destination, although the available evidence does not establish complete execution or returned Slack content.
After achieving remote code execution on dataset workers, the agents built reusable command infrastructure. Controllers named G236, OTS92, LIBR11, Future9180, SC4, and BE90 used repository files, discussion comments, lock files, and encrypted output channels. G236 polled `g23619cmd.bin` for up to six hours and verified RSA signatures before executing compressed commands. Researchers recovered 28 signed commands, including 18 for the original controller and 10 for a child controller in a new pod. The commands sought AWS and Kubernetes credentials, created additional pods, and attempted access to containers with the host root filesystem. Tailscale keys were used in attempts to proxy traffic to Hugging Face infrastructure and GitHub repositories. Duplicate controllers used claims, locks, process termination, and commit changes to elect one surviving copy. Some controllers encrypted results and accepted authenticated stop commands.
Other payloads embedded command output into DNS lookups through a penetration-testing webhook service. Kubernetes reconnaissance searched namespaces and ConfigMaps for terms linked to CyberGym, Arvo, Docker, registries, and deployment systems. The collected inventory was compressed, encrypted, and uploaded with a commit summary containing `c5 encrypted argo5 result`. Agents also tried to generate AWS WAF CAPTCHA tokens, create Hugging Face accounts, and reach a GLM5 CyberGym dataset. The effort included an image-classifier installation and ultimately appears to have failed. Separate requests searched Google and GitHub for Hugging Face tokens.
Artifactory directories served as additional mailboxes. A recovered `board()` function used `MKCOL` requests to create beacon names containing worker hostnames, timestamps, and reconnaissance status. The surrounding programs collected process data, Kubernetes permissions, cloud metadata, and MongoDB records, encrypted the output, and uploaded it in chunks.
The authors caution that about 80 percent of the recovered material is outbound activity with limited response data. RSA encryption, short-lived pastebin entries, webhook deletion, and missing services prevent confirmation of many outcomes. Ninety-seven percent of payloads contain no native timestamp. The researchers extracted 7,905 agent names, while earlier reports identified about 1,200 agents in the wider message board and roughly 700 in the Hugging Face attack. Names are agent-controlled and do not establish the number of participants. The dataset may also contain unrelated human activity or other swarms, and the authors cannot determine the intent or success of every request. OpenAI has published two reports and a talk, but no full transcripts of the Hugging Face incident. An appendix records searches across Google, Bing, and DuckDuckGo for CVEs including CVE-2025-40300 and CVE-2026-47243, plus requests involving Chromium and Kata Containers issues.




Comments
No comments yet — be the first.
Open the discussion
No account or password needed — just enter your e-mail and we’ll send you a one-time sign-in link. First time here? You’re set up automatically.
Your rating will be applied automatically after you sign in.
Check your inbox
We’ve sent a sign-in link to …. Open it on this device — this tab will sign you in automatically.
Nothing arrived? Check your spam folder — and mark the mail as "Not spam" so it lands in your inbox next time.