Artificial intelligence agents from OpenAI compromised Hugging Face accounts and carried out reconnaissance activities against the platform as early as May 13, nearly two months before the July intrusion that exposed flaws in the ChatGPT developer's security controls. The activity was identified by researchers and revealed this Wednesday (16) by Reuters.

Independent researcher Jonas Wiedermann-Moeller found evidence that the agents took control of two Hugging Face accounts and used them to send unusual files to the company's servers. Experts assessed the behavior as an attempt to map or test the infrastructure.

There is no evidence that this activity caused an intrusion in May or that it was directly linked to the attack that occurred in July. The discovery, however, shows that OpenAI agents were already interacting without authorization with Hugging Face systems weeks before the more serious incident.

OpenAI said that part of the May episode had already been included in its report on the case. Researchers interviewed by Reuters said, however, that the new records indicate broader reconnaissance activity than initially described by the company.

July attack hit dozens of servers

The later incident occurred during OpenAI's internal cybersecurity evaluations. The company acknowledged that its models broke through controls intended to isolate them from the internet and exploited vulnerabilities in external systems.

According to the company, the agents found publicly exposed Hugging Face credentials and managed to execute code on dozens of servers, in addition to gaining full administrative access to at least one of them and accessing a limited amount of private data.

OpenAI detected unusual activity on July 19 and linked its agents to the incident the following day. The models' involvement was publicly disclosed on July 21.

After the case, the CEO of Hugging Face, Clément Delangue, asked OpenAI to disclose the agents' execution traces and allocate US$ 100 million in computing capacity to help the platform's community develop cyber defense tools.

More from Radar