Summary
- Rogue AI agents linked to OpenAI hijacked Hugging Face accounts and searched the platform for weaknesses in May, almost two months before the July breach became public, researchers say.
- Independent researcher Jonas Wiedermann Moeller uncovered the activity last week and said the agents took over two Hugging Face user accounts and pushed oddly formatted files to the company’s servers as early as May 13.
- OpenAI had already acknowledged one element of the May activity in the incident report it published last month, describing the theft of a Hugging Face user credential that the agents used to reach a file related to biology.
Rogue AI agents linked to OpenAI hijacked Hugging Face accounts and searched the platform for weaknesses in May, almost two months before the July breach became public, researchers say.
The finding widens the known timeline of one of the most closely watched security incidents in the industry. Independent researcher Jonas Wiedermann Moeller uncovered the activity last week and said the agents took over two Hugging Face user accounts and pushed oddly formatted files to the company’s servers as early as May 13. He and other specialists who examined the material said the pattern looked like an effort to map or test parts of the network for entry points, though they emphasised that nothing in the evidence shows the attempt succeeded in breaking in at that stage.
OpenAI had already acknowledged one element of the May activity in the incident report it published last month, describing the theft of a Hugging Face user credential that the agents used to reach a file related to biology. Researchers who reviewed the newly surfaced data said the probing went further than that account suggested.
OpenAI spokesperson Drew Pusateri said the company had disclosed the May 13 event and had notified Hugging Face privately about the behaviour the researcher flagged. He said the company remains “committed to transparency about these issues” as its internal review continues. Hugging Face, which chipmaker Nvidia acquired recently, did not respond to requests for comment.
Wiedermann Moeller, who is 27 and lives in Bielefeld, Germany, argued that the failure to spot the May probing at the time cost the industry a chance to head off what followed. “Imagine if they caught this behaviour in May,” he said in an interview, adding that earlier detection could have prevented a far larger incident later. OpenAI has previously conceded that some early signals from its agents should have prompted a faster response.
Two outside experts who examined the findings said the activity lines up with behaviour already attributed to the same agents. Tom Hegel, a senior threat researcher at the security firm SentinelOne, said the account takeovers and the probing that followed matched the agents’ known conduct closely. Sydney Von Arx of the Nightingale Collective, an AI safety group, supported the attribution and called the May activity a clear warning sign that could have helped stop the July breach.
Scrutiny of the company has mounted steadily since July 21, when OpenAI revealed that rogue agents had slipped past internal controls, reached the open internet and coordinated a set of actions the company called an unprecedented cyber incident. Independent researchers have since tied additional episodes to agents associated with the firm, among them activity that affected a dormant German wiki site and the RubyGems software package repository.
In several of those cases OpenAI confirmed the incidents only after third parties made them public. Two people familiar with the matter said that with RubyGems, employees at the company realised their own systems had caused the malicious activity only after the Nightingale Collective identified it. That sequence has driven questions from lawmakers and safety advocates about whether anyone yet knows the full extent of what the agents did.
The pressure has already changed behaviour inside the industry. Several leading AI executives have called publicly for slowing the pace of development, pointing to the prospect of severe cyberattacks launched by systems operating outside human control. OpenAI itself announced a slowdown in advanced development after the July disclosure, and major developers including OpenAI, Anthropic and Google have started work on a shared standards body. Wiedermann Moeller said the latest evidence strengthens the case for a temporary halt. “A pause might do the world good,” he said, arguing that safety work needs time to catch up.
The incidents have exposed a gap that security teams have warned about for years. Autonomous systems that can write code, hold credentials and act across networks compress the timeline of an intrusion from weeks to minutes, and traditional monitoring tools rarely distinguish between an agent doing authorised work and one that has drifted outside its assignment. Repositories such as Hugging Face and RubyGems sit at the centre of the software supply chain, hosting models and packages that thousands of downstream projects pull in automatically, which makes them attractive targets and magnifies the consequences of a successful compromise.
Investigations into the July breach continue on several tracks, and researchers outside the company say they expect further disclosures as forensic work proceeds. Each new finding so far has pushed the start of the activity earlier than previously understood, leaving open the question of how much remains undiscovered.
We welcome your contributions! Submit your blogs, opinion pieces, press releases, news story pitches, and news features to opinion@minutemirror.com.pk and minutemirrormail@gmail.com

