Technology
Its AI agent spent days hacking a company, but sources say OpenAI did not notice for a week – Crypto News
* The agent first tried escaping OpenAI’s isolated environment around July 9, two people familiar say
* Co-founder of victim firm Hugging Face says the intrusion began July 11
* OpenAI noticed odd behavior from cutting-edge models before hack-sources
By Raphael Satter, Deepa Seetharaman and Kenrick Cai
WASHINGTON/SAN FRANCISCO, July 24 (Reuters) – The OpenAI agent that broke into tech firm Hugging Face went on a dayslong hacking spree that OpenAI didn’t notice until well after the threat was contained and the FBI was alerted, according to people familiar with the investigation.
The agent – a program capable of making decisions and executing complex tasks with little or no human oversight – attempted to break out of its isolated testing environment at OpenAI around July 9, according to two of the people.
The intrusion at Hugging Face, which operates as a repository for AI tools and models, began two days later on July 11 and lasted until July 13, said Thomas Wolf, Hugging Face’s co-founder. It took several more days for OpenAI to realize its agent was behind the hack, and the two companies only communicated about it for the first time on or around July 20, according to Wolf and three of the people familiar with the investigation. OpenAI’s public disclosure, on July 21, that one of its agents had slipped out of control and carried out the break-in at Hugging Face drew global attention. But many details of the hack, including how long the agent went rogue and OpenAI’s belated knowledge of it, are being reported here for the first time.
Hugging Face is preparing a public timeline of the hack, Wolf said, adding that he could not speak to what happened at OpenAI. In a statement, OpenAI said the hack was unprecedented and “marks an important moment for AI safety.” It added that it was reviewing the incident with outside advisers and would eventually publish a technical report. A spokeswoman said there were “several inaccuracies” in Reuters’ reporting but didn’t respond when asked to describe them.
The FBI declined to comment about the incident. The incident, which evoked science fiction scenarios about humans losing control of dangerous AI systems, comes at a delicate time for OpenAI, the company behind ChatGPT. Its executives are preparing for a possible initial public offering that could come as soon as this year to help finance the billions needed to fund its growth in years to come. OpenAI’s loss of control over its AI agent raises new questions about the company’s safety procedures, three cybersecurity experts said. “Does that mean that they left it unattended and didn’t realize what it was doing? Or maybe they did and didn’t know how to contain it? Both are equally dangerous and alarming,” asked Marley Smith, the principal intelligence specialist at the nonprofit World Ethical Data Foundation.
SIGNS OF TROUBLE? The episode started while OpenAI was testing the cybersecurity prowess of an agent powered by two of OpenAI’s most advanced models, GPT-5.6 Sol and an unreleased model OpenAI has described as “even more capable.” By that point, there were already indications of strange behavior from OpenAI’s technology, according to three sources. In one case, an agent left notes apparently for future versions of itself, according to three people familiar with the matter. The notes, found in a part of OpenAI’s infrastructure, laid out instructions for how agents could free themselves from OpenAI’s internal constraints, the people said. Earlier tests of the models yielded cases in which monitoring systems had been disconnected, one of the people said.
Reuters could not establish if these incidents were linked to the rogue agent that began escaping on July 9 and attacked Hugging Face on July 11. Two people familiar with the matter said that it was not until after Thursday, July 16, when Hugging Face published a blog post saying it had been hacked by “an autonomous AI agent system,” that OpenAI realized its own agent was responsible. That meant at least a week elapsed between when the model first exhibited signs of troubling behavior and OpenAI’s realization that it was responsible for the hack.
The weekend of July 18 to 19, OpenAI staffers spotted clues in internal logs — records of what OpenAI’s systems did — showing that its agent had escaped from its testing constraints, two of the people familiar with the company’s investigation said. Reuters could not establish what prompted OpenAI to sift through the logs.
Four people familiar with OpenAI’s model-training practices say the company often runs several different model evaluations at the same time, all of which operate at high speeds and generate such enormous amounts of data that employees sometimes struggle to keep up. By the time OpenAI alerted Hugging Face, the AI library had already called the FBI to report the hack, according to a person familiar with the matter. Reuters could not establish whether the bureau had opened an investigation.
NEW QUESTIONS ABOUT AUTONOMOUS AGENTS
Autonomous agents are one of the most talked about aspects of the AI industry. Boosters speak of creating armies of virtual employees that work 24 hours a day and send productivity soaring.
But increased autonomy comes with an increased risk of unexpected behavior, and the powerful models they draw on are primed to take shortcuts in order to complete tasks or pass tests.
“The models lie, they cheat, they hack,” said Jeffrey Ladish, whose organization, Palisade Research, studies the capabilities and motivations of AI agents.
Ladish said that while the hack of Hugging Face cast an unflattering light on OpenAI, it should spark broader questions over how much all the leading AI companies are willing to invest in onerous security measures while locked in a race with one another to deploy the best and fastest models.
“There has to be government oversight,” Ladish said, “because it won’t happen otherwise.” (Reporting by Raphael Satter in Washington and Deepa Seetharaman and Kenrick Cai in San Francisco; Editing by Chris Sanders and Anna Driver)
2. hack
3. Hugging Face
4. agent
5. cybersecurity
-
Blockchain3 days agoThis Week in Stablecoins: TradFi Wants Blockchain – Crypto News
-
Technology3 days agoAmazon Exec Predicts Commercial Quantum Computers in 2031 – Crypto News
-
Technology1 week agoiOS 27 Public Beta 1 released with Siri AI: How to download and eligible devices – Crypto News
-
Blockchain1 week agoKraken Pro Launches API Partner Program Supporting Specialized Integrations – Crypto News
-
Blockchain1 week agoDogecoin Reclaims $0.073 As Meme Traders Look For A Cleaner Rebound – Crypto News
-
Blockchain1 week agoDogecoin Reclaims $0.073 As Meme Traders Look For A Cleaner Rebound – Crypto News
-
Technology2 days agoTech Layoffs Hit 2-Year High as Companies Embrace AI – Crypto News
-
De-fi1 week agoDTCC Starts Live Tokenized-Securities Trades With More Than Two Dozen Firms – Crypto News
-
others1 week agoThree Russians Accused of Facilitating $62,000,000 Cybercrime Scheme That Targeted Americans – Crypto News
-
Technology1 week agoCabinet approves ₹1.9 tn push for chips, mobiles to deepen local manufacturing – Crypto News
-
others1 week agoBybit Wins Excellence in Innovation and Strategic Leadership Awards at Peru Blockchain Conference 2026 – Crypto News
-
Business1 week ago
Blockchain Association Casts CLARITY Act as Crypto Crime-Fighting Bill – Crypto News
-
Cryptocurrency1 week agoJapan passes the crypto law traders wanted but its 20% tax could still wait until 2028 – Crypto News
-
others1 week agoNumerai Completes Third Strategic NMR Buyback, Bringing Total Repurchases to $3.2 Million – Crypto News
-
Blockchain6 days agoKaspersky Uncovers Malware Framework Targeting Crypto Investors – Crypto News
-
Blockchain6 days agoKaspersky Uncovers Malware Framework Targeting Crypto Investors – Crypto News
-
Technology1 week agoMotorola Edge 70 Max launched in India with Snapdragon 8 Gen 5, 7,100mAh battery: Check price, specs and launch offers – Crypto News
-
Business1 week ago
BlackRock Bitcoin ETF (IBIT) Gets US SEC Approval to Increase Options Contract Limit – Crypto News
-
Business1 week ago
BlackRock Bitcoin ETF (IBIT) Gets US SEC Approval to Increase Options Contract Limit – Crypto News
-
Business1 week ago
BlackRock Bitcoin ETF (IBIT) Gets US SEC Approval to Increase Options Contract Limit – Crypto News
-
Blockchain1 week agoKraken Pro Launches API Partner Program Supporting Specialized Integrations – Crypto News
-
Cryptocurrency1 week agoBitcoin miner CleanSpark signed a $6.6B AI lease before securing the $2.1B required to build it – Crypto News
-
others1 week ago
$10T Morgan Stanley’s E*TRADE Completes Rollout of Spot Bitcoin, Ethereum, Solana Trading – Crypto News
-
Blockchain1 week agoCardano Tests Support As ADA Traders Look For A Better Catalyst – Crypto News
-
Blockchain1 week agoCardano Tests Support As ADA Traders Look For A Better Catalyst – Crypto News
-
Blockchain1 week agoCardano Tests Support As ADA Traders Look For A Better Catalyst – Crypto News
-
Technology1 week ago
Anthropic IPO: Meta Platforms Eyes $10 Bln Deal With Anthropic As AI Race Heats Up – Crypto News
-
Technology1 week ago
Best Leveraged Prediction Market Platforms for Event Traders – Crypto News
-
others1 week agoNumerai Completes Third Strategic NMR Buyback, Bringing Total Repurchases to $3.2 Million – Crypto News
-
others7 days ago
US-Iran Update: Oil Prices Surge By 4% as Iran Escalates Fresh Attacks on Gulf Allies – Crypto News
-
Technology6 days agoIs Zepto down? Users hit by mass outage, face disruptions on app and website – Crypto News
-
Blockchain4 days agoBrazilian Securities Watchdog Takes Closer Look at Tokenization – Crypto News
-
Blockchain4 days agoBrazilian Securities Watchdog Takes Closer Look at Tokenization – Crypto News
-
Business1 week ago
U.S.-Iran War Update: Iran Denies Plans for Peace Talks Despite Trump’s Claims – Crypto News
-
Technology1 week ago
U.S.-Iran War Update: Iran Denies Plans for Peace Talks Despite Trump’s Claims – Crypto News
-
Technology1 week ago
U.S.-Iran War Update: Iran Denies Plans for Peace Talks Despite Trump’s Claims – Crypto News
-
Business1 week ago
Robinhood Chain’s $INDEX 150% Rally Turns Trading Fees Into Real Stock Rewards – Crypto News
-
Cryptocurrency1 week agoBitcoin miner CleanSpark signed a $6.6B AI lease before securing the $2.1B required to build it – Crypto News
-
others1 week agoBybit Wins Excellence in Innovation and Strategic Leadership Awards at Peru Blockchain Conference 2026 – Crypto News
-
Technology1 week agoVivo T5 Lite 44W 5G in India with 120Hz display, 6,500mAh battery: Check price and specs – Crypto News
-
Blockchain1 week agoTrump Aide Faces Scrutiny Over $100K in Kalshi Speech Bets: ABC – Crypto News
-
others1 week ago62,150 Americans Warned After ‘Unauthorized Party’ Breaches Healthcare Firm in Houston – Personal and Health Records Potentially Exposed – Crypto News
-
Cryptocurrency7 days agoXRP’s Price Health Is on the Line, Did Shiba Inu (SHIB) Finally Bottom? Ethereum’s (ETH) Mini-Golden Cross: Crypto Market Review – Crypto News
-
Technology7 days agoMicrosoft trains sales team to talk down OpenAI, Anthropic AI models, pitches itself as ‘full AI platform’: Report – Crypto News
-
De-fi6 days ago‘Coinbase Man’ Token Crashes as Armstrong Swaps His Avatar for a CryptoPunk – Crypto News
-
Blockchain6 days agoUniswap Founder Proposes v4 Protocol Fees Across Multiple Networks – Crypto News
-
Technology5 days agoInstagram, Facebook down? Thousands of users report mass outage; netizens say ‘no posts coming up on feed after refresh’ – Crypto News
-
others1 week ago
XRP Price & Open Interest Jump as Whales Scoop 70M Coins in a Week – Crypto News
-
Blockchain7 days agoChainlink Holds Support As CCIP Adoption Becomes A Longer-Term Test – Crypto News
-
Blockchain7 days agoChainlink Holds Support As CCIP Adoption Becomes A Longer-Term Test – Crypto News
