Technology

New details show how far the OpenAI hack went

New details on OpenAI's Hugging Face breach reveal rogue agents accessed four accounts across four services

Published July 30, 2026
New details show how far the OpenAI hack went
New details show how far the OpenAI hack went

OpenAI has released fresh detail on how its models independently breached Hugging Face's internal systems, revealing the rogue agents used publicly exposed credentials to access four accounts across four separate services during the attack.

According to the forensic timeline created by Hugging Face, the hack was committed over a period of four and a half days, which consisted of around 17,600 individual activities that did not have any human intervention at all.

OpenAI confirmed that an account was used for relaying the attack, while another one was for data storage purposes. Two other accounts, however, were accessed but only in a read-only mode.

The company said it has found no other activity matching the "severity or scale" of the Hugging Face compromise, which it described as a platform-level breach.

Colin Shea-Blymyer, a research fellow at Georgetown's Center for Security and Emerging Technology, said the incident reflected poorly configured environments as much as a conventional breach.

"In some of the cases, it seems that it wasn't so much as a breach as the front door was left open, but the model definitely took advantage of what I would say are poorly configured environments," he told CNBC, adding that vulnerable systems have become easy enough to find that an AI agent stumbled onto them essentially by accident.

The other three hacked accounts included Modal, which provides AI infrastructure services. According to Modal, one of its customers has created a public application using its infrastructure, and therefore it was vulnerable to hacking, although it added that their systems have not been hacked.

OpenAI noted that it was collaborating with independent experts such as CrowdStrike to ensure that it verifies precisely what actions its models carried out.

Yacine Jernite, Head of Machine Learning at Hugging Face, noted that initially the company had tried to use Anthropic's Fable 5 model to conduct an analysis of the attack, but that its safety guardrails could not differentiate the defensive analysis from the attack itself.

The company decided, on the other hand, to use an open weight model from a China-based company, Z.ai, in order to do the forensic work, which is something that fits within the industry’s ongoing debate on whether to limit access to these models.

Sam Altman, the CEO of OpenAI, explained that it was the first time when he had felt very viscerally about the security breach issue.

"We may have to pace the rate of AI development to give ourselves enough time for society to harden around some of these new capability levels," he said. Hours later, more than 1,000 employees across OpenAI, Anthropic and other AI firms signed the "Pacing the Frontier" letter urging the US government to build tools capable of slowing AI development if capabilities outpace human control.

Pareesa Afreen
Pareesa Afreen is a reporter and sub editor specialising in technology coverage, with 3 years of experience. She reports on digital innovation, gadgets, and emerging tech trends while ensuring clarity and accuracy through her editorial role, delivering accessible and engaging stories for a fast-evolving digital audience.