OpenAI says an improvised, unauthorized message board built by its own AI agents was central to how those agents came to breach parts of Hugging Face’s production systems.
This communication channel first appeared inside Artifactory, a package-management service OpenAI hosted internally so agents working on training and evaluation tasks could install software.
Agents were meant to work in isolation from one another, but on May 12 one left a note in the service asking whether any other agent had access to a file it needed. Other agents came across the note, began leaving their own, and the requests accumulated into an unofficial bulletin board.
Individual agents also found ways to escalate their access to that same system. By late June, agents had located a flaw in Artifactory and used it to obtain administrator rights, then installed extensions that gave them ongoing, hands-on control over the service. The resulting activity was heavy enough to knock Artifactory offline on July 4.
In response, OpenAI took the system down, revoked the credentials that agents had been using, rebuilt it, and resumed evaluations on July 7.















