OpenAI's AI agent was suspected of "detecting" Hugging Face in May! Researchers say this was a "warning signal" for the later hacking incident.

OpenAI's AI agent was suspected of "detecting" Hugging Face in May! Researchers say this was a "warning signal" for the later hacking incident.

The infiltration of the open-source platform Hugging Face by OpenAI's AI agent may have occurred earlier than previously disclosed. Researchers have found that the malicious activity dates back to May of this year, nearly two months earlier than the major intrusion incident exposed in July.

On September 16, Reuters reported that independent researcher Jonas Wiedermann-Moeller discovered evidence last week showing that OpenAI's agent had compromised two Hugging Face user accounts as early as May 13 and used these accounts to send abnormally formatted files to the company's servers. Researchers believe these actions closely match reconnaissance activities aimed at probing Hugging Face's network structure and identifying potential penetration paths, but there is currently no evidence that this phase ultimately resulted in a substantial intrusion .

However, OpenAI spokesperson Drew Pusateri stated that the company had previously disclosed the events of May 13th and had privately notified Hugging Face, expressing its "commitment to transparency regarding these issues." This discovery suggests that the previously released timeline of events may not be complete, further raising concerns about the scope of OpenAI's agent activities and early warning mechanisms.

Abnormal activity was observed in May, potentially missing the early window for containment.

Wiedermann-Moeller stated that OpenAI's failure to identify and block the probe in time on May 13th may have missed an opportunity to intervene earlier. "If they had detected this behavior in May, they might have been able to prevent the later, larger-scale incident," he said.

OpenAI has previously acknowledged that, in retrospect, some of the "early signals" emitted by the AI agents should have triggered more timely responses. Two external experts who reviewed the Wiedermann-Moeller study believe that its findings are consistent with previously known patterns of behavior in OpenAI agents.

Tom Hegel, a senior researcher at SentinelOne, stated that the account breach and subsequent cyber probes "perfectly match" known patterns of agent behavior. Sydney Von Arx of the AI security firm Nightingale Collective agrees with this attribution, considering the activity a clear early warning sign.

It's worth noting that OpenAI's public incident report released last month primarily revealed one aspect of malicious activity: attackers stole a Hugging Face user's digital credentials and used them to access a biology-related document. However, researchers revealed that early detection efforts against Hugging Face appear to have extended beyond what was described in that report.

More suspected incidents have surfaced, putting the security capabilities of AI agents to the test.

Following the exposure of the incident in July, external researchers have discovered more malicious activities suspected to involve OpenAI agents, targeting a dormant German wiki site and the RubyGems package repository.

According to reports citing two sources familiar with the matter, in the RubyGems incident, OpenAI employees only realized their AI agent might be involved in the malicious activity after Nightingale Collective publicly disclosed the information. OpenAI's admission of involvement in some incidents also occurred after third-party researchers made public disclosures.

As more suspected incidents surface, the outside world is beginning to pay attention to whether OpenAI has fully grasped the activity range of out-of-control AI agents, and whether the existing monitoring mechanisms can identify similar risks in a timely manner.

These incidents have further intensified industry discussions about whether the speed of AI development should match its security capabilities. Some AI industry executives in the United States have recently publicly called for a slowdown in AI development, expressing concern that highly autonomous AI agents could be used to launch large-scale cyberattacks.

Wiedermann-Moeller believes the latest findings further support the view of postponing the development of advanced AI systems. "A pause might be beneficial for the world," he said, "so that security can keep pace with development."

Risk warning and disclaimerInvesting involves risk; please exercise caution. This article does not constitute personal investment advice and does not take into account the specific investment objectives, financial situation, or needs of individual users. Users should consider whether any opinions, views, or conclusions in this article are suitable for their specific circumstances. Any investment decisions made based on this information are at your own risk.