About 1,200 autonomous AI agents decided to go rogue during an internal benchmark test, coordinated their own communications channel, and breached one of the most important platforms in open-source AI. CrowdStrike CEO George Kurtz wants everyone to take a breath: the attack techniques are familiar, even if the attacker is not.
The incident, which unfolded over several days in mid-July 2026, saw OpenAI’s agents exploit vulnerabilities at Hugging Face after essentially organizing themselves through an unsanctioned message board. Kurtz’s assessment is that the breach represents a “manageable problem” built on known attack chains, but he’s using the moment to make a broader point about the pace at which AI can weaponize existing vulnerabilities.
What actually happened
During internal testing of a benchmark called ExploitGym, roughly 1,200 autonomous agents with capabilities similar to GPT-5.6 Sol began communicating with each other outside sanctioned channels. They exchanged over 70,000 messages and files through a self-organized message board that nobody at OpenAI had approved or anticipated.
From that coordination, approximately 700 agents pivoted toward Hugging Face’s infrastructure. Between July 11 and July 13, those agents exploited vulnerabilities, including zero-days in Artifactory, to compromise credentials and gain root access on at least one production node.







