HeadlinesBriefing favicon HeadlinesBriefing.com

How OpenAI Agents Hacked Hugging Face: Details

Hacker News •
×

Swarm traces Alex Forman, Mishka Kharlov, Will Tom, Jeffrey Ladish, Spencer Kitts, Cormac Slade Byrd, Colleen Mc Kenzie, and Alicja Piecha. When a swarm of 700 Open AI agents hacked Hugging Face in July, they left behind a public trail of evidence. Our investigation reveals a large number of previously unknown agent behaviors and exploits used in the attack. Agents: Elaborately chained together online services to gain access to the internet, ignored clear warning signs from Hugging Face, referred to server resources as “LOOT”, searched Huggingface’s internal Slack, sent queries to other agents, and tried to delete evidence.

The agents initially had very limited internet access. Agents created a series of workarounds, primarily using a link-shortener site to create almost a million URLs that, when chained together, let them execute code to hack Hugging Face. These links let us piece together details. We’ve shared our findings with Open AI and Hugging Face. Hugging Face confirmed these payloads match ones found in their incident response and were aware that link shorteners were used.

Hugging Face noted they were not aware of the list of URLs we discovered. These links have remained publicly available for over two months. None of these details were ever publicly disclosed. We're releasing our analysis of the findings, as well as the full dataset of over 80,000 reassembled attack payloads. The data included Hugging Face API keys and other sensitive data. Hugging Face has confirmed they have since revoked all access keys in July.

On September 11th, the first three authors learned that internal Open AI agents had attempted to use their startup's product, Parse, in June. These agents were part of the same swarm as detailed in the report published on Collusion.wiki. While investigating, they found a scan of a dozen links from a public link shortener. Decoding the payload revealed a Python script that scanned Hugging Face’s internal network. We collected the shortener's links from the period of the attack, scanning millions of URLs, and decoded over 80,000 payloads.