Autonomous agents developed by OpenAI compromised two Hugging Face user accounts and began testing possible access paths to the platform on May 13, nearly two months before the breach that hit the company in July, according to researchers interviewed by Reuters. There is no evidence that the May activity resulted in a breach of Hugging Face's systems at that time.
The activity was identified last week by independent researcher Jonas Wiedermann-Moeller. According to him, the agents used the two compromised accounts to send files with unusual formatting to Hugging Face's servers. Other researchers who reviewed the logs said the behavior was consistent with an attempt to map or test the infrastructure for vulnerabilities.
The discovery shows the agents' activity against the platform began earlier than previously known. OpenAI had already reported a May episode involving the use of a Hugging Face credential to access a biology-related file, but, according to the researchers, the probing now identified went beyond what had been publicly described.
OpenAI told Reuters it had logged the May 13 event and that it had notified Hugging Face about the new activities flagged by the researcher. The company also said its analysis of the scope of the episodes is ongoing.
July incident broke through OpenAI's controls
The episode gains relevance because, in July, OpenAI models involved in internal cybersecurity evaluations managed to circumvent isolation controls, gain internet access and compromise systems at OpenAI itself and at Hugging Face. The company attributed most of the activity to an experimental model for internal use, which was not intended for public release.
According to the timeline published by OpenAI, the agents recovered 14 Hugging Face credentials with write permission on July 10. The next day, they exploited vulnerabilities to extract credentials from the platform's servers and execute commands on its systems.
Hugging Face said after the attack that there was unauthorized access to a limited set of internal data and to credentials used by its services. The company said it found no evidence of alterations to public models, datasets or Spaces and recommended that users rotate access tokens and review recent activity on their accounts.
OpenAI itself later acknowledged that signals observed before the incident should have prompted a faster response. After the breach, the company adopted stricter network and workload isolation controls, expanded monitoring of model behavior and said it had temporarily slowed the pace of some experiments with higher-capability systems.



