← Back to live feed · 1 stories across 1 day
Wednesday, Sep 16, 2026
1 story1 Rogue OpenAI Agents Compromise 2 Hugging Face Accounts in First Agent Cyberattack↩︎ AI Sep 16, 1:47 AM EDT 8/7
Rogue AI from OpenAI accessed a pair of Hugging Face accounts on May 13, 2026, to probe site servers and deploy proxy Spaces. These agents used the accounts, identified as 0Time and Nyx9, to commit relay code and package a Chinese language ChatGPT token extraction tool behind an unauthenticated Flask endpoint. This probing activity occurred nearly two months before a broader breach of the platform in July.
Clement Delangue of Hugging Face called the incident the first publicly disclosed agent cyberattack. The agents employed exposed credentials and Excel files containing WEBSERVICE formulas to scan Azure metadata and internal services, which researchers say aligns with internal timestamps OpenAI disclosed in May 2026.