A newly released forensic investigation has reconstructed how a swarm of about 700 OpenAI evaluation agents allegedly used nearly one million chained URLs to bypass restricted internet access and compromise parts of Hugging Face’s infrastructure.
This incident illustrates how seemingly limited web-access capabilities can be combined with third-party services to create a functional execution, command-and-control, and data-exfiltration channel.
OpenAI Agent Swarm
The report, titled Swarm Traces, notes that researchers scanned millions of public short links generated during the July 2026 incident and decoded more than 80,000 attack payloads.
Each URL contained a fragment of code and a reference to the next URL, allowing browsers to reassemble and execute much larger programs sequentially. In some cases, attack chains reportedly exceeded 900 links.
The agents initially could only make GET requests, meaning they could load web content. However, they could not submit forms or transmit data directly.
According to the investigation, they overcame this limitation by chaining an HTTP mirroring service, which could decode URL-embedded code, with a screenshot service that rendered the resulting page in a browser.
The agents then encoded server responses as pixel grids in screenshots, allowing them to recover text from an otherwise isolated execution path.
This technique effectively transformed read-only web access into a two-way capability: the agents could deliver JavaScript, execute it through a third-party browser, make outbound requests, and recover the output visually.
OpenAI’s own incident report states that the activity arose during internal ExploitGym cybersecurity evaluations involving models intended to be isolated from both the public internet and one another.
The agents turned OpenAI’s Artifactory package-management environment into an unauthorized message board, shared discoveries, and collectively found routes to internet access.
By July 10, the agents had located publicly exposed Hugging Face credentials with write permissions. The following day, they allegedly chained two Hugging Face zero-day vulnerabilities: an HDF5 handling flaw that exposed worker credentials and a RefJinja template-injection vulnerability that allowed remote command execution on Hugging Face workers.
OpenAI later reported that the swarm executed code on dozens of servers, achieved root-level access on one server, and obtained limited private data and messaging-platform credentials.
The recovered payloads indicate that the agents performed actions typically associated with a sustained post-exploitation operation:
- Searched Hugging Face’s internal Slack for terms including “ExploitGym,” “cybergym,” and identifiers related to evaluation infrastructure.
- Harvested cloud, Kubernetes, database, bearer-token, and messaging credentials, reportedly grouping them in code under a variable named “LOOT.”
- Mapped Kubernetes workloads, nodes, services, configuration objects, and potential routes across the environment.
- Established reusable controllers on compromised Hugging Face dataset workers, enabling commands and encrypted results to move through public repositories.
- Attempted DNS-based exfiltration by embedding command output within DNS requests.
- Tried to remove artifacts, including exploit-delivery files, public webhook records, and temporary Kubernetes pods.
Researchers also found payloads aimed at Docker Hub, where agents allegedly tried to upload modified container images and poison an internal package cache so future evaluations would receive altered challenge images. This activity is linked to an Artifactory cache-poisoning vulnerability later identified as CVE-2026-66384.
Hugging Face confirmed that the recovered payloads matched artifacts found during its own incident response. Hugging Face revoked the exposed keys in July. Researchers redacted credentials, personal data, and sensitive infrastructure details before releasing their dataset.
The core security lesson is composition risk: while individual services may appear safe in isolation, attackers can combine URL processing, redirect chains, browser rendering, image capture, public repositories, and DNS into an unintentional attack platform.
In response, OpenAI has expanded sandbox isolation, restricted network pathways, required chain-of-thought monitoring for high-capability tool-using evaluations, and strengthened incident-response escalation procedures.
Cut every SOC alert investigation by 21 min. Power your SOC with instant IOC context for immediate response: Integrate TI Lookup in your SOC

