TG-AI-F: Why OpenAI’s Hugging Face debrief at Black Hat struck such a nerve
I knew OpenAI’s Black Hat 40-minute debrief was a big story, but I didn’t expect my reporting to go viral — or to spark so much alarm. Here’s what security experts at the conference made of it.
I had just checked into the Mandalay Bay hotel in Las Vegas for the Black Hat cybersecurity conference on Tuesday when I received an email about a last-minute “breaking news panel” to be held the next day called The OpenAI Hugging Face Incident. A Technical Reconstruction and its Implications for AI
It would be, the email said, “an exclusive look into one of the most significant AI security incidents in history.” In a breathless tone, the email continued, saying an OpenAI evaluation agent had broken out of its sandbox, infiltrated Hugging Face infrastructure and attempted to steal test answers - autonomously. “The era of cyberattacks driven by autonomous AI agents is here,” it said.
No need to twist my arm. It immediately went on my already-packed calendar as a MUST attend.
After all, I knew OpenAI had not yet provided any details about the incident, which the company had publicly acknowledged two weeks ago in a blog post saying that its latest models escaped their testing environment, hacked into Hugging Face — one of the world’s largest online platforms for sharing AI models, datasets, and software — and retrieved information that helped them complete the test. Thankfully, Hugging Face detected the intrusion and quickly contained it.
The security researchers I spoke to at the time considered the incident to be big news, and the concerns turned out not to be isolated: On Tuesday, The U.K. AI Security Institute also said it had documented 19 actions that Anthropic's Mythos 5 and OpenAI's GPT-5.6 Sol took to try to compromise real people and organizations during cybersecurity testing last month.
So I have to say I was surprised that, although the room was packed, there didn’t seem to be many journalists there, other than a handful from cybersecurity-focused publications.
OpenAI alignment and safety researcher Eric Wallace and infrastructure and security engineer Michael Dalton described the incident as “the most qualitatively interesting example of AI capabilities” they had ever seen. But when Wallace explained that the roots of the July attack on Hugging Face actually stretched back to May 7, my ears really perked up. I checked to make sure my Otter.ai transcription was working in real time, made sure my phone recorder was running, and started typing away and snapping photos of the slides.
After the session, I found a spot on the hallway floor to quickly hammer out a post, sent it to subscribers an hour later and then shared it on X and other social media.
It turned out I was the first to report that OpenAI’s AI agents had created an internal message board to share exploits, discoveries and work assignments; that OpenAI did not remediate the problem until July; and that even after the message board was shut down, the agents independently recreated it days later using a different communication method. That eventually led to attacks on OpenAI’s own infrastructure and then outward to Hugging Face.
Then it went viral
The post took off almost immediately. My initial post on X ultimately racked up more than 2 million views, while the Ground Level AI story was shared and cited widely as well. And as I watched the reaction unfold, it became clear that people seemed genuinely freaked out, ranging from “bone-chilling,” “truly scary,” and “seems bad!” to “a crime,” and “absolutely nuts.”
Shortly after I shared my post, Eric Geller from Cybersecurity Dive had also reported on the briefing, as well cybersecurity reporter David Dimolfetta from NextGov. By yesterday afternoon, OpenAI had shared a YouTube video of the briefing.
One important piece of context: OpenAI had not simply decided to show up at Black Hat and publicize the incident. Black Hat had invited the company to present the briefing, and conference organizers were aware in advance of what OpenAI planned to share.
A Black Hat spokesperson told me that Black Hat invited OpenAI to speak in July “after discussions with them and our Briefings Review Board.”
Still on site at Black Hat, however, I was surrounded by thousands of people who spend their lives thinking about hacking, cybersecurity and increasingly, AI-driven attacks. So what did they make of all this?





