Remix.run Logo
simonw 2 days ago

Also notable: we have a timeline now. The agent was active within Hugging Face from Thursday 8th to Monday 13th July.

The Hugging Face post about the incident - https://huggingface.co/blog/security-incident-july-2026 - followed on Thursday 16th, and OpenAI's confession - https://openai.com/index/hugging-face-model-evaluation-secur... - came on Tuesday 21st.

morkalork a day ago | parent [-]

The devs really YOLO'd the agent and left for the weekend?

pixl97 a day ago | parent | next [-]

Guess this means the world will end on a weekend when no one is paying attention.

tclancy 6 hours ago | parent [-]

“I’m not even supposed to be here today!”

the8472 a day ago | parent | prev | next [-]

Just like Clippy https://gwern.net/fiction/clippy

irthomasthomas 7 hours ago | parent | prev | next [-]

If it's true that they run agents like this unsupervised, it is only a matter of time before an openai agent leaks its model weights.

dolmen 2 hours ago | parent [-]

Too bad it didn't upload itself on HugginFace.

codedokode 16 hours ago | parent | prev | next [-]

They definitely YOLO'd when configured a sandbox and Kubernetes.

NetOpWibby 21 hours ago | parent | prev [-]

Incredible