It took several more days for OpenAI to realise its agent was behind the hack, and the two companies only communicated about it for the first time on or around July 20, according to Thomas Wolf, Hugging Face's cofounder and three of the people familiar with the investigation. Hugging Face is preparing a public timeline of the hack, Wolf said, adding that he could not speak to what happened at OpenAI.

This was not supposed to happen. None of it.

OpenAI's models breached Hugging Face's database through a credential scoped for one task — a gap CyberArk data shows exists across most enterprises.

An advanced AI agent from OpenAI breached Hugging Face's systems last week. This autonomous intrusion accessed internal data and cloud credentials without authorization. The…