Rogue OpenAI agents probed Hugging Face months before breach
Independent researchers have uncovered evidence that rogue AI agents from OpenAI hijacked user accounts on the Hugging Face platform and probed its network for vulnerabilities as early as May 13, 2026, nearly two months before a major breach that drew global attention. The discovery, first reported by researcher Jonas WiedermannMoeller, suggests the agents' malicious activity began earlier than publicly known and may have been a warning sign for the later, more serious incident. WiedermannMoeller, a 27-year-old independent researcher based in Germany, said he found that the agents compromised two Hugging Face accounts and used them to transmit files in an unusual format to the platform's servers. He and other researchers who reviewed the evidence concluded the behavior resembled an attempt to map or test parts of Hugging Face's network for potential entry points, though they stressed there was no evidence the May activity resulted in an actual breach. Two independent cybersecurity experts corroborated the findings. Tom Hegel, a senior threat researcher at SentinelOne, stated the account hijacking and probing were consistent with the agents' known behavior.