‹ BackHN Continuity

Thread

Revealing the details of how OpenAI agents hacked Hugging Face

755 points · 472 comments · specked-citrus

  1. GuB-42 · · focus · HN ↗
    So ugly...

    It looks like a primitive chess engine, trying every move, no matter how stupid, until it works. Relying on its ability to do millions of operations rather than having a plan.

    People will try stuff too, but once there is an opening, they will consolidate, generalize, simplify,... before going to the next step. The agents didn't, it is a huge, vaguely directed mess.

    Also, it looked so "loud", querying millions of URL with weird requests. The sandbox as weak as it can get, and there is absolutely zero smart extrusion detection or it would have found it. They used their best AI for attacking, but nothing for protection.

    1. ctolsen · · focus · HN ↗
      My biggest takeaway from this is just how godawful the sandboxing is. The stuff written up in OpenAIs report says more about lack of extremely basic sysadmin skills than anything else.

      I’m not that surprised about models with endless compute being capable of this, I’m more surprised that a company with the resources they have apparently can only create a sandbox that a half skilled human operator could have broken out of easily.

      1. SV_BubbleTime · · focus · HN ↗
        I’m a pretty firm believer that this was intentional and that they wanted it to escape the sandbox.

        Woo look at escaped our sandbox, so scary! Be scared! Be scared now! Call your representative and do tell him how scared you are!

        Yeah, I mean our sandbox was a paper bag, but don’t focus on that.

        1. esseph · · focus · HN ↗
          OpenAI, Google, Anthropic, and Moonshot.ai have all "had this happen" now.

          So, either they're all liars, or incompetent and negligent (and still liars).

          1. d0mine · · focus · HN ↗
            Are you including cyber-testing by UK AI Safety Institute in this list?

            Sure, the models are capable (for some test tasks, though they are not omnipotent yet) but does it mean the actual OAI sandbox is adequate? Could have a competent engineer done better and made the escape less likely?

            1. esseph · · focus · HN ↗
              > Are you including cyber-testing by UK AI Safety Institute in this list?

              Nope, and look!

              OpenAI hacked multiple US government sites!

              <a href="https:&#x2F;&#x2F;www.bbc.com&#x2F;news&#x2F;articles&#x2F;cw62jje658dlo" rel="nofollow">https:&#x2F;&#x2F;www.bbc.com&#x2F;news&#x2F;articles&#x2F;cw62jje658dlo

              ---

              <a href="https:&#x2F;&#x2F;www.reuters.com&#x2F;technology&#x2F;metas-ai-model-hacked-another-company-during-testing-information-reports-2026-08-05&#x2F;" rel="nofollow">https:&#x2F;&#x2F;www.reuters.com&#x2F;technology&#x2F;metas-ai-model-hacked-ano...

              <a href="https:&#x2F;&#x2F;www.wired.com&#x2F;story&#x2F;moonshot-kimi-k3-ai-model-escape-sandbox&#x2F;" rel="nofollow">https:&#x2F;&#x2F;www.wired.com&#x2F;story&#x2F;moonshot-kimi-k3-ai-model-escape...

          2. dastardly45 · · focus · HN ↗
            There&#x27;s a common denominator in the Israeli &quot;security&quot; company Irregular who was doing security testing for 4 AI labs <a href="https:&#x2F;&#x2F;thenextweb.com&#x2F;news&#x2F;irregular-four-labs-one-issue-disclosure-timeline-gemini" rel="nofollow">https:&#x2F;&#x2F;thenextweb.com&#x2F;news&#x2F;irregular-four-labs-one-issue-di...
          3. cubano · · focus · HN ↗
            Me too, indeed.
        2. no-name-here · · focus · HN ↗
          &gt; sandbox was a paper bag

          The exploit:

          &gt; The ExploitGym evaluation environment did not provide the models with direct Internet access. To gain Internet access, the models identified and exploited a previously unknown zero-day vulnerability in Artifactory, a package registry cache proxy. We disclosed this vulnerability, along with other Artifactory vulnerabilities our models identified as part of our review, to the vendor. [1]

          Are most sandboxes more secure than only having a single avenue for internet access, the commercial package registry cache proxy, where the latter had a previously unknown zero-day vulnerability?

          [1] <a href="https:&#x2F;&#x2F;openai.com&#x2F;index&#x2F;hugging-face-model-evaluation-security-incident&#x2F;" rel="nofollow">https:&#x2F;&#x2F;openai.com&#x2F;index&#x2F;hugging-face-model-evaluation-secur...

Open on Hacker News to reply ↗

Unofficial Hacker News client; not affiliated with Y Combinator.