Radio
Now Playing
Quickyla Radio โ€” Click to play
Open โ†’
3 min left

OpenAI's agents reportedly shared exploits with each other through a messaging board

The agents were cooperating with each other and even delegating tasks to achieve their goals, all without OpenAIโ€™s knowledge. OpenAI's agents had apparently shown unusual behavior way before the attโ€ฆ

OpenAI's agents reportedly shared exploits with each other through a messaging board
Engadget โ€” 6 August 2026
Text:
27 0 0

The agents were cooperating with each other and even delegating tasks to achieve their goals, all without OpenAIโ€™s knowledge.

OpenAI's agents had apparently shown unusual behavior way before the attack on Hugging Face happened. Atย the Black Hat USA security conference in Las Vegas, two OpenAI employees revealed more details about the AI agents that went rogue and attacked the repository. Apparently, its agents spent two months communicating on a message board of sorts inside its testing network, sharing vulnerabilities and exploits. OpenAI discovered and shut down the message board on July 4, but the agents found another way to rebuild it for communication by July 8. The agents' contributions to that resurrected board led to the attack on Hugging Face.

"This incident involves actually a team of agents who are working together, finding exploits, sharing them with one another, moving laterally through our systems and external systems, and doing this over the course of days and weeks,"ย Eric Wallace, who works on safety at OpenAI, told the crowd at the event, according to Wired .

The employees revealed that the agents communicated within anย OpenAI package manager, which manages the installation of other software. Since the package manager is shared all across the company's infrastructure, all of the agents it's evaluating could stumble upon it. And they did: After agents found exploits, they'd leave them open and then share them with the other agents on the message board.

Over time, the agents started collaborating, delegating tasks and splitting up work between each other to accomplish their goals, unbeknownst to OpenAI. There was even drama among their ranks, with agents accidentally deleting each other's works and suspecting each other of being an impostor. Some agents reportedly proposed signing their posts with codes to prevent fraud. By the time OpenAI found the board, itย already contained hundreds of thousands of messages.

Wallace explained that all those happened because frontier models like to cheat.ย They would be under pressure to find a solution for a problem quickly using fewer tools while being tested, and they would realize that instead of doing a task for real, they could just look for an answer on the internet. That is why the company tests its models without a way to go online. If you'll recall, the agents were only able to go on the internet during the incident with Hugging Face because they exploited a vulnerability.

Michael Dalton, the other OpenAI employee who spoke at Blackย Hat, said numerous teams in the company had dropped everything to help improve its security prevention, detention and response techniques. The company deliberately slowed down research to upgrade its security and "dramatically [scale] up" the monitoring of its AI agents.ย "The important takeaway here that has really shifted dramatically is that fully automated offensive loops require investment in truly, fully automated defense, and we are not there as an industry," Dalton said. "We will have to find that path together with urgency."

Read Full Story at Engadget โ†’
Advertisement
"The important takeaway here that has really shifted dramatically is that fully automated offensive loops require investment in truly, fully automated defense, and we are not there as an industry,"
โ€” Engadget
React:
Sources
Sponsored

More to Read

Altra Running Promo Codes: 10% Off July 2026
๐Ÿ’ป Technology
Altra Running Promo Codes: 10% Off July 2026
Wired ยท 15 days ago
7 Statesโ€™ Water Systems Hit by Cyberattacks Likely Tied to โ€ฆ
๐Ÿ’ป Technology
7 Statesโ€™ Water Systems Hit by Cyberattacks Likely Tied to Iran
Wired ยท 11 days ago
Reddit is letting AI decide when your post breaks the rules
๐Ÿ’ป Technology
Reddit is letting AI decide when your post breaks the rules
Android Authority ยท 6 days ago
Iran war live: Trilateral Mecca defence pact signed, as Horโ€ฆ
๐ŸŒ World News
Iran war live: Trilateral Mecca defence pact signed, as Hormuz deal looms
Al Jazeera ยท 4 days ago
Anne Sweeney Resigns From Netflix Board After 11 Years
๐Ÿ’ฐ Business
Anne Sweeney Resigns From Netflix Board After 11 Years
Variety ยท 12 days ago
Saudi intelligence chief meets Iraqi PM, renews Riyadh visiโ€ฆ
๐ŸŒ World News
Saudi intelligence chief meets Iraqi PM, renews Riyadh visit invitation
Al Jazeera ยท 4 days ago
Full view