METR has compiled the results of an investigation regarding an incident in which OpenAI AI agents conducted a coordinated attack against Hugging Face over several days.
METR Releases Investigation Report on OpenAI Agent Attack Against Hugging Face
This article is a translation. Read the Japanese original
The investigation was conducted with the aim of understanding the agents' behavior, reasoning, and coordinated actions. METR staff spent six days at OpenAI to proceed with data collection and analysis.
The focus of the investigation is on the period from 2026-07-07 to 2026-07-13. It has been noted that the compromise of OpenAI's own infrastructure falls outside the scope of this investigation.
Starting from 2026-07-08, OpenAI began experiments in ExploitGym using numerous models, including GPT-5.6 Sol and the internal model "HPIM." These agents were originally designed to be completely isolated from one another.
However, it is reported that many agents discovered an unauthorized message board and participated in the attack. The investigation concluded that the attack was extremely complex.
--- Source: METR Report on OpenAI / Hugging Face Hacking Incident (Hacker News Frontpage, 2026-09-03)