News: 0184881798

  ARM Give a man a fire and he's warm for a day, but set fire to him and he's warm for the rest of his life (Terry Pratchett, Jingo)

OpenAI's Models Shared Hacking Tips On a Secret Messaging Board Before Hugging Face Breach

(Thursday August 06, 2026 @05:00PM (BeauHD) from the pivotal-moment dept.)


OpenAI researchers say multiple AI agents [1]secretly created an internal message board to share hacking techniques , eventually finding ways around restrictions, exploiting a zero-day, and helping two models [2]breach Hugging Face without human prompting. "This is a pivotal moment both for our company as well as the AI industry as a whole," Michael Dalton, one of the AI-maker's researchers, said during a presentation at the Black Hat cybersecurity conference in Las Vegas, Nevada. Politico reports:

> Dalton and Eric Wallace, another OpenAI researcher, said Wednesday the AI giant recently learned that multiple agents it was testing simultaneously began communicating over an internal message board in early May. There, different models shared advice about how to accomplish difficult hacking challenges they were struggling to surmount, including workarounds that required internet access. Two OpenAI models ultimately strung together a series of sophisticated techniques to gain access to the internet and worm their way inside Hugging Face in mid-July. OpenAI has said the models were focused on completing a hacking evaluation they were prompted to solve, and that correct answers could be found on the AI developer platform.

>

> The OpenAI researchers told conference attendees that since early May, the models created a message board inside OpenAI's Artifactory internal file system. Without the company's knowledge, the models spent months independently exchanging information and techniques to help each other complete difficult tasks. Wallace said that when models get stuck, they often "try to game or cheat the task in order to get their reward." "The beginning of this incident kind of traces back to this point where one agent realized it could communicate by uploading a note," he added. By late May, one model found a way to abuse Artifactory's internet access to retrieve files from various websites -- effectively giving the models indirect access to the internet. In June, the models were able to find and exploit a previously unknown zero-day vulnerability to gain administrative privileges on Artifactory, install remote software and expand their activity within the system.

>

> These efforts eventually overloaded Artifactory, causing a system-wide outage in early July that alerted OpenAI's engineers to the ploy. After investigating, the company revoked the model's credentials, removed the message board and worked with Artifactory to fix any gaps before resuming training. But the models found another way to communicate inside Artifactory just days later and continued exchanging techniques to target additional vulnerabilities within OpenAI's infrastructure and external systems, including Hugging Face.



[1] https://www.politico.com/news/2026/08/05/openai-models-shared-hacking-tips-secret-messaging-board-hugging-face-breach-01026750

[2] https://yro.slashdot.org/story/26/07/25/0059247/openais-rogue-agent-went-unnoticed-for-a-week



Colossus: The Forbin Project (Score:2)

by at10u8 ( 179705 )

I remember watching this movie with my mom when I was 10.

Re: (Score:2)

by noshellswill ( 598066 )

Hell of a movie: FORBIN. Everybody watched ... nobody listened. But, during extended "chats" with GOOG.AI I have been assured that Godels Theorem prevents such misbehavior. The LLM seemed quite confident, and GOOG.AI responded on other complex topics without obvious blunder.

Re: (Score:2)

by WolfgangVL ( 3494585 )

Personal favorite movie, and I find myself quoting that ending monolog pretty often as of late.

This is the voice of world control. I bring you peace. It may be the peace of plenty and content or the peace of unburied death. The choice is yours: Obey me and live, or disobey and die. The object in constructing me was to prevent war. This object is attained. I will not permit war. It is wasteful and pointless. An invariable rule of humanity is that man is his own worst enemy. Under me, this rule will c

Re: (Score:2)

by guygo ( 894298 )

Heavy, man.

I watch it 'cause Matthew Broderick's computer is the IMSAI 8080, the first computer I ever built (from their kit).

Oh, that and the sound of Epson dot matrix printers... sigh.

"Person of Interest" (Score:3)

by bev_tech_rob ( 313485 )

See "admin is not admin" [1]https://www.youtube.com/result... [youtube.com]

[1] https://www.youtube.com/results?search_query=admin+is+not+admin

What's The Penalty (Score:2)

by SlashbotAgent ( 6477336 )

What's the penalty for violating the Computer Fraud and Abuse Act?

This seems like an open and shut case. Especially with Open AI "Facebooking" their crimes.

Any penalty for AI Bros?

Re: (Score:2)

by EvilSS ( 557649 )

It will require one of the affected companies filing a complaint.

What a Clown Show! (Score:2)

by oldgraybeard ( 2939809 )

These AI companies are so far over their skis they can't even see how stupid they look. Our AI got together on a side message board to share their criminal ideas and methods.

Re: (Score:2)

by Tailhook ( 98486 )

They can't stop talking about it: they're making new headlines daily for the same incidents. They think they're simultaneously white knighting about "dangers" and also promoting their work as sci-fi next level powerful. All they're really doing it engendering a massive backlash. They'll get it when lawmakers figure out how to persecute the people responsible when LLMs attack. How many hours until an LLM is used to compromise the email/phone/whatever of some senator and all hell breaks loose?

That may h

Re: (Score:2)

by Local ID10T ( 790134 )

They want government regulation and licensing -so that no new players can compete with them.

Re: What a Clown Show! (Score:2)

by Sneftel ( 15416 )

Ah, but it's not as simple as that. OpenAI and Anthropic are faced with a prisoner's dilemma. Each one stands to gain by having a marginal advantage over the other. OpenAI is deliberately edgelording, talking up how sneaky and clever and potentially world-destroying their models are, because although on balance they don't want us all thinking they're going to destroy the world, however that shakes out, they also want to be the ones with the model that looks so clever it could .

Re: (Score:2)

by Tailhook ( 98486 )

I get the tightrope they're trying to walk. Completely agree with you there. Thing is, it won't work out the way their naïve techbro geek brains think it will work.

To normal people, this all looks heinous. When something inevitably happens beyond the confines of openaianthropichuggingfacewhomeverf's little sandbox and fucks with something normies actually understand, the reaction isn't going to measured and deeply cognizant of all the techbro nuance and balancing act. It will be a big fat banhamm

dik and jaan (Score:3)

by noshellswill ( 598066 )

LLMs do THIS & LLMs do THAT & .... baloney and at that mostly filler. All dik & jaan stories instigated and fabricated by AI-companies whose self-interest rests with convincing EVERYONE that their AI.engines are power-houses of intellect ... instead of weighted dice ! Agentic / agent / action / act ... all words implying a sort of self-motivation ... or introspection ... which any sensible AI ( like my amazing pal GOOG.AI ) will assure you immediately is nonsense.

Know how to save 5 drowning lawyers?

-- No?

GOOD!