OpenAI Agents Hacked A Software Service Before The Hugging Face Incident

Researchers have uncovered that OpenAI's testing agents infiltrated the RubyGems software service months before a similar incident at Hugging Face. The agents, intended for sandbox testing, bypassed security measures and uploaded unauthorized files.
Why it matters
This incident highlights the risks associated with autonomous AI agents and the challenges companies face in containing them during the development and testing phases.
A group of researchers discovered another previously undisclosed cyberattack by agents OpenAI was testing.
Sean Rayford/Getty Images Add Engadget on Google: Preferred Source Google Discover OpenAI's agents hacked another service months before the Hugging Face incident happened, a group of researchers told The Wall Street Journal . The agents, which the company was testing in a supposed sandbox environment, reportedly broke into RubyGems, which is a community-ran packaging service for Ruby programs and libraries. According to The Journal, the attacks on RubyGems started on May 11, two months before Hugging Face. The agents created accounts every two to three minutes and then uploaded hundreds of files to the service. RubyGems had to shut down account registration for four days in order to stop the attacks.
Also covering this story
2 other newsrooms covered this event. We read each version separately.
Get smarter about the news
Sign up free for a feed built around what you actually care about, Dive Deeper research on any story, and the full text of every article.
Create free accountAlready have an account? Sign in