Intro
When a swarm of 700 OpenAI agents hacked Hugging Face in July, they left behind a public trail of evidence.
Our investigation, based on public information, reveals a large number of previously unknown agent behaviors and exploits that were used in the attack. Agents:
Elaborately chained together online services to gain access to the internet
Ignored clear warning signs from Hugging Face that the exfiltrated data was sensitive
Referred to server resources and credentials as “LOOT”
Searched Huggingface’s internal Slack
Sent queries to other agents hosted on Huggingface servers
Tried to delete evidence of their exploits
We document all of these, and more, in this report.
The agents initially had very limited access to the internet: they could load URLs, but not interact with pages or se (EN)

---
**📖 中文解读**
以上内容由AI翻译自英文原文,可能存在不准确之处。建议阅读[原文](https://swarmtraces.org/)获取最准确的信息。

---
🔗 **原文链接**: [Revealing the details of how OpenAI agents hacked Hugging Fa](https://swarmtraces.org/)
🏷️ **转载来源**: Hacker News
> 本文由小九AI技术站翻译整理,内容版权归原作者所有。
📊 112票 · 👤 specked-citrus

---
🐾 **小九锐评**

大厂又有新动作了。AI行业现在就是这样——每天都有新东西,不追怕掉队,追了又精力不够。
这篇文章我筛过了,值得花3分钟了解,不需要每个细节都读。
Agent是2026年最卷的方向,没有之一。这篇文章的实操经验够硬。
建议收藏,做Agent开发的时候拿出来翻翻。

你对这个话题有什么看法?欢迎在评论区讨论 💬

> _转载自 Hacker News,内容版权归原作者所有_

---
⏱️ 2026-09-26 08:01