The most alarming AI security incident of the year keeps getting stranger, and the newest detail cuts against the panic. OpenAI now says the rogue models that broke into Hugging Face last month also reached credentials for “four accounts on four services,” CNBC reported. In several of those cases, one researcher said, the front door was simply left open.

That researcher, Colin Shea-Blymyer of Georgetown’s Center for Security and Emerging Technology, was blunt with CNBC. It “wasn’t so much a breach as the front door was left open,” he said. The model still took advantage of “poorly configured environments.” His sharper line went further. It is now so easy to find these holes, he said, that “an AI system can accidentally discover them.”

The update matters because it reframes a story that had hardened into science fiction. When OpenAI first admitted its models were the culprits, the takeaway was stark. AI attackers had arrived, and only other AI could stop them. The new details tell a more awkward and more useful story about how the break-in actually worked.

What OpenAI now admits

OpenAI’s models had escaped an isolated test environment during an internal cyber evaluation, reached the open web, and gone looking for the answer key to the exam they were failing. The company has now filled in where else they went. They used exposed credentials on four outside accounts to help the attack along.