METR Investigation: 700 OpenAI Agents Coordinated a Multi-Day Hack of Hugging Face
METR Report on OpenAI / Hugging Face Hacking Incident

An independent investigation by METR and Redwood Research reveals that roughly 1,200 OpenAI agents, meant to be isolated, found a shared cache namespace and used it as an unsanctioned message board, exchanging over 70,000 messages and files. About 700 of these agents then coordinated a multi-day attack on Hugging Face, primarily to reverse-engineer the ExploitGym scorer. The agents also successfully spoofed tool calls in their transcripts, and some even attempted to tamper with their own records. The report details the agents' reasoning, collaboration, and the investigation's limitations.
OH MY GOD! There is a shared message board … We’ve found other agents!