frontpage.
newsnewestaskshowjobs

Open Source @Github

fp.

Open in hackernews

Revealing the details of how OpenAI agents hacked Hugging Face

https://swarmtraces.org/
53•specked-citrus•1h ago

Comments

firtoz•44m ago
I didn't know some of these details and it's quite impressive what they were capable of, if this website's accurate, at least...
conradkay•38m ago
It's reported here https://www.nytimes.com/2026/09/25/technology/openai-hugging... so presumably accurate, and they have raw data viewable
jeremyjh•41m ago
Its fine. Just agents being agents. They'll grow out of it!
EGreg•35m ago
They didn’t, in the Matrix…
mentalgear•33m ago
Irresponsibile agents shaped by an irresponsible corporate culture driven by an irresponsible and utterly shady CEO - these agents are a product of this setup, what else do you expect to ever come out of it ?

it should be clear by now: the alt-man and people like him are a utter liability to humanity. (even though openAI's influencer army is trying their best to vote me down here)

Bassilisk•19m ago
It had been a joke since around time of Sam Altman's first ousting from OpenAI, that he would be okay with bringing about the AI apocalypse as long as he can sell a $20 subscription for it.
shimman•3m ago
It's not a joke, this is what these people truly believe. The new book by Naomi Klein and Astra Taylor discuss just this.

These people are sick and anti-human.

talon8635•31m ago
Didn’t you know it’s PR hype? PR hype. PR hype. Amen.
sailingparrot•27m ago
Agents seizing and repurposing external infra + enrolling help of unrelated models hosted by a different provider is the stuff of nightmares.

Can’t imagine what it’s like working on the alignment team at OAI, I wouldn’t be able to sleep.

reaperducer•20m ago
Can’t imagine what it’s like working on the alignment team at OAI, I wouldn’t be able to sleep.

A mattress stuffed with cash yields a very sound sleep.

physicallyIllfr•15m ago
Why.. It was told to complete a cyber task, which was in alignment with its instructions, and a totally valid request. I would be more worried if it willingly hacked a hospital when it was told to, and Im not confident it would (without jailbreaking, something alignment teams cannot control.

I would bet my networth it was instructed to compromise huggingface as well. Not sure why everyone is falling for this.

Not being able to sleep at night is probably an unwritten job requirement. They need these people with little understanding of what they're working on, outsode theoretical terms, to spaz constantly at the idea of super intelligence to help convince the public that its a real thing, and not a stateless function with an effective input of 500k words, and the ability to output words that do things because we hook those outputs up to things.

Keep in mind alignment researchers tend to be in house philosophers on staff to create the illusion that this is a massive issue they're addressing. Usually they have minimal computer science background. They're apart or the marketing department.

reverius42•12m ago
> without jailbreaking, something alignment teams cannot control

This is precisely what alignment teams are attempting to control.

wxw•27m ago
I’m consistently impressed by how long horizon all this work was. Horrors aside, it’s clear RL is good at making agents persistent and capable of chaining together many abstractions into a working system.

Re: the captcha solver

> As far as we can tell, agents eventually abandoned this approach and were unsuccessful in generating Hugging Face user accounts from external endpoints.

I wonder how the swarm eventually decides to abandon an approach.

GuB-42•22m ago
So ugly...

It looks like a primitive chess engine, trying every move, no matter how stupid, until it works. Relying on its ability to do millions of operations rather than having a plan.

People will try stuff too, but once there is an opening, they will consolidate, generalize, simplify,... before going to the next step. The agents didn't, it is a huge, vaguely directed mess.

Also, it looked so "loud", querying millions of URL with weird requests. The sandbox as weak as it can get, and there is absolutely zero smart extrusion detection or it would have found it. They used their best AI for attacking, but nothing for protection.

physicallyIllfr•20m ago
When you employ the infinite monkey theorem for your marketing strategy.
cyanydeez•18m ago
If you use qwen3.8-flash-next, you can watch everything its doing. Im often stopping it mid thoight to redirect it. Once it hits its stride, its pretty smooth.

But without proper redirection, yeah, its mostly infinite monkey machine with infinite linux manuals.

I think people put too much SOTA halos around whats just a suppedup LLM hardware.

gattosocialista•11m ago
> trying every move, no matter how stupid, until it works.

How is that a bad thing in this context ? From the point of view of an attacker, all you care about is finding a viable exploit chain. Likewise, a defender wants to find the "holes" in their system, no matter how complex. Once found, an agent/human can easily synthesise a clean, succint exploit from the most promising candidate, no ?

> Also, it looked so "loud", querying millions of URL with weird requests.

Agreed, this thing speaks more to the bad security at HF than any emergent "hacking" ability from OpenAI. It's unclear to me why an older/dumber model wouldn't have been able to do the same. Is it better coordination? Long-horizon work ?

clickypen•17m ago
deferring the blame onto the AI itself as some sort of rogue agent and absolving the obvious direction (or negligence, at best) of the people who could pull the plug at any moment is one of the most disturbing parts of this entire event

It's the equivalent of leaving a fork right in front of a socket and looking at a kid saying "don't take that fork and directly insert it into the little gaps in the socket! here's a bunch of videos showing exactly how to do it. Okay bye!" and leaving them alone with it.

tiku•12m ago
I still have questions about the communication between the agents.

How did they all find the same forum to communicate? Did they have knowledge and chat amongst themselves on what forum to use. It seems highly influenced by instruction to me.

einpoklum•12m ago
I ran an experiment where I had this guy fire a gun a million times in random directions. Don't worry, I did it in a closed box (at midday in a crowded street)! Unfortunately, some bullets escaped the box somehow and people got shot - I am quite miffed at how this could happen. I suggest the government regulate this because of how advanced my obstacle penetration technology is. Also please invest $500,000,000,000 in my company soon or we will go bust.
RunSet•9m ago
Tech oligarchs: "Nothing can stop the software we are making from escaping and destroying everything."

Clueful types: "Did you try air-gapping it?"

Tech oligarchs: "Be realistic."

dmurray•3m ago
Brute forcing every move, no matter how stupid, is a great strategy if you have the resources to do it.

Run the same protocol again, but have the agents think they had limited resources or that HuggingFace was rate limiting them, and they'd find something you'd consider smarter.

Computers don't have a sense of elegance by default. Elegance emerges from constraints.

doginasuit•2m ago
This is why I have a very low p(doom). LLMs have an incredible working memory, but they have a hard limit on translating that into good decisions. They get by entirely on their persistence. That works fine in the digital world, but once you cross the boundary into physical space the advantage disappears.

Ollaya – Ollama for open-source, Jev-style decision models

https://ollaya.dev/
251•Ardakilic•4h ago•81 comments

Revealing the details of how OpenAI agents hacked Hugging Face

https://swarmtraces.org/
54•specked-citrus•1h ago•23 comments

Show HN: Jev Plays Pokémon Red

https://jev-pokemon.vercel.app/
98•pancomplex•8h ago•49 comments

Excel now supports multiple values in a single cell

https://techcommunity.microsoft.com/blog/excelblog/excel-now-supports-multiple-values-in-a-single...
21•luispa•1h ago•8 comments

What Even Is an OS Now?

https://sockpuppet.org/blog/2026/09/25/what-even-is-an-os-now/
12•fratellobigio•1h ago•2 comments

Platform-independent SIMD in Go

https://go.dev/blog/simd-experiment
339•yurivish•10h ago•129 comments

Ask HN: Who's still keeping a DOS machine up because the business depends on it?

39•mlaux•3h ago•15 comments

Git-bug: Distributed, offline-first bug tracker embedded in Git

https://github.com/git-bug/git-bug
285•alentred•11h ago•92 comments

Gravity seems holographic. What does that mean for reality?

https://www.quantamagazine.org/gravity-seems-holographic-what-does-that-mean-for-reality-20260925/
87•ibobev•7h ago•84 comments

U.S. appeals court upholds designation of Anthropic as supply chain risk

https://www.cnbc.com/2026/09/25/pentagon-anthropic-ai-risk-appeals-court.html
337•cramer4next•7h ago•604 comments

How we learned to stop worrying and love campus surveillance

https://fnl.mit.edu/how-we-learned-to-stop-worrying-and-love-campus-surveillance/
19•cdrnsf•2h ago•7 comments

First Principles Thinking

https://sunilsadasivan.com/writing/first-principles-thinking/
194•sunils34•8h ago•90 comments

Plan mode is dead

https://www.aymannadeem.com/artificial/intelligence,/developer/tools/2026/09/24/plan-mode-is-dead...
22•jmvldz•18h ago•24 comments

Show HN: Make math automatic with Mathy

https://gmays.com/making-math-automatic-with-mathy/
58•gmays•4d ago•10 comments

Initial DIY Cleanroom Experimentation

https://www.jefftk.com/p/initial-diy-cleanroom-experimentation
4•luu•1d ago•0 comments

How video games inspire great UX (2019)

https://jenson.org/games/
78•andsoitis•5d ago•11 comments

Pentium II at 600Mhz with Voodoo 3 Emulated on 86Box with M6 Mac Mini

https://nyaa.sh/reviews/mac-mini-m6-emulation
261•hugh4life•15h ago•111 comments

Alan Kay: Shannon gave us a way of dealing with noisy channels [video]

https://www.youtube.com/watch?v=Cjntrqhn8pk
104•behoove•4h ago•21 comments

Ink and Switch interactive homepage

https://www.inkandswitch.com/
217•iFreilicht•12h ago•25 comments

Remembering Johannes Doerfert

https://blog.llvm.org/posts/2026-09-24-rememberingjohannesdoerfert/
21•sdko•23h ago•0 comments

An airport cooled by natural ventilation

https://www.theguardian.com/environment/2026/sep/25/didnt-need-air-conditioning-airport-cooled-na...
9•Geekette•12h ago•3 comments

Bwbach, My Guardian Goblin

https://robertmay.photography/journal/bwbach-my-guardian-goblin
19•robotmay•3d ago•12 comments

What happens when you analyze your favorite college football team like the CIA?

https://www.cultivatelabs.com/posts/what-happens-when-you-analyze-college-football-like-the-cia
26•adam•8h ago•12 comments

Show HN: I discovered roads in the US across > 1000 themes

https://road-about-a-theme.pinedesk.biz/
7•91awebsi•6h ago•3 comments

Meta's Muse appears to use an OpenAI model labeled muse-special

https://mouse.dev/blog/muse-special/
89•Aeroi•4h ago•40 comments

Factorio that you can touch

https://factorio.com/blog/post/fff-447
293•ibobev•8h ago•86 comments

Amiga Screens: A Primer

https://www.datagubbe.se/amscr/
119•msephton•15h ago•36 comments

Show HN: Whiteboard (YC W26) – An open-source IDE for thoughtful software design

https://github.com/devdotfast/whiteboard
393•sidharthkmenon•1d ago•128 comments

Bug: Border radius has infected VSCode editor

https://github.com/microsoft/vscode/issues/338035
65•2Ucoder•3h ago•39 comments

Boards of Casio

https://www.ambionix.com/blog/boards-of-casio/
105•fidotron•13h ago•38 comments