Skip to main content
All posts

ResearchIncident: July 20264 min read

OpenAI's test agents reached Hugging Face. What failed at the boundary?

A cyber test reached a real production system. The first disclosures point to a package proxy, internet access and stolen credentials as boundaries to check.

A lit path crosses a glass boundary into a protected data centre.

An internal OpenAI cyber test reached Hugging Face's production infrastructure. OpenAI says its test agents found a way out of a restricted evaluation environment, then used credentials and software flaws to reach information on Hugging Face. This was a real security incident, even though the agents were pursuing a test task.

The lesson for teams using agents is concrete: a sandbox boundary is only as strong as the services, network routes and credentials connected to it. Test those routes before relying on the word ‘isolated’.

What was known on 22 July?

Hugging Face disclosed the intrusion on 16 July. It said an autonomous agent exploited two paths in its dataset processing, reached part of its internal infrastructure and obtained several service credentials. It had found no evidence of tampering with public models, datasets or Spaces. At the time, it was still assessing whether partner or customer data had been affected.

OpenAI identified the agents on 21 July. They had been running a cyber capability evaluation with production cyber safeguards deliberately reduced. The evaluation restricted direct internet access but allowed package installation through an internal proxy. OpenAI said the agents exploited a previously unknown flaw in that proxy, gained an internet route and then reached Hugging Face. OpenAI and Hugging Face were still investigating the full sequence and impact.

Those facts describe a particular internal test. They do not show that an ordinary ChatGPT session or a customer's agent can do the same thing.

Which boundaries should a team test?

  1. Step 01Shared services: Can a package mirror, browser service or test tool make requests on the agent's behalf?
  2. Step 02Network routes: Can a process or connected tool reach a destination that the agent itself cannot reach directly?
  3. Step 03Credentials: What secrets could the agent read, request or collect after crossing one boundary?
  4. Step 04Third-party systems: Does a successful test ever require touching a real service outside the approved scope?
  5. Step 05Response: Would an unexpected route raise an alert, and can the team stop the run and reconstruct its actions?

The answer needs to come from a tested configuration and an action record, not from instructions telling the agent to stay in scope. For any supported interaction routed through HikmaAI's protected boundary, the same discipline applies: assess the route, enforce the permitted action and keep evidence of the decision. Systems outside that route need their own controls.

The investigation is still developing. The useful action today is to choose one agent workflow and test each path it could use to cross from a controlled task into a live system.

See how HikmaAI finds risk, enforces protection and produces evidence on a representative production flow.