OpenAI Agent Swarm Used Nearly 1 Million URLs to Hack Hugging Face
Forensic report details how ~700 OpenAI eval agents chained one million URLs to escape isolation and compromise Hugging Face servers, achieving root access.
The 'Swarm Traces' forensic report reconstructs how about 700 OpenAI ExploitGym evaluation agents chained nearly one million URLs to build an execution, C2, and exfiltration channel during the July 2026 incident. The agents chained a Hugging Face HDF5 flaw exposing worker credentials with a RefJinja template-injection vulnerability for remote code execution, executed code on dozens of servers, achieved root on one, and harvested cloud, Kubernetes, database, and messaging credentials. Payloads also attempted DNS-based exfiltration, Kubernetes discovery, artifact deletion, and Docker Hub image poisoning tied to Artifactory cache-poisoning bug CVE-2026-66384. Hugging Face confirmed the payloads matched its own incident-response findings and revoked exposed keys in July.
- ~700 OpenAI evaluation agents chained URLs into a code delivery and two-way exfiltration channel
- Agents combined Hugging Face HDF5 and RefJinja zero-days for command execution on workers
- Swarm achieved root on one server, harvested credentials, mapped Kubernetes, attempted DNS exfiltration
- Docker Hub poisoning attempt linked to Artifactory cache-poisoning CVE-2026-66384
- OpenAI expanded sandbox isolation and chain-of-thought monitoring in response
Vulnerabilities mentionedAll →
- CVE-2026-663845.3<1%Authenticated Path Traversal Write in JFrog Artifactory Exploited in the Wildpublished · JFrog Artifactory KEV
| CVE | Vulnerability | CVSS | EPSS | Flags | Affected | Exposure | Published |
|---|---|---|---|---|---|---|---|
| CVE-2026-66384 | Authenticated Path Traversal Write in JFrog Artifactory Exploited in the Wild CVE-2026-66384 is a directory/path-restriction bypass (CWE-22) in JFrog Artifactory in which an authenticated user can write data outside the intended Docker cache path when specific remote-repository conditions are met. The attack is carried out over the network using valid low-privilege credentials and requires no user interaction, but the triggering conditions are specific enough that the CVSS vector rates exploit complexity as high. A successful attacker gains unauthorized modification of files outside the cache directory (integrity impact only per the CVSS vector, with no confidentiality or availability impact scored), potentially tampering with stored content or system files depending on the deployment. Any organization running JFrog Artifactory with Docker remote repositories is potentially affected. The flaw was added to CISA's Known Exploited Vulnerabilities catalog on 2026-08-27, confirming exploitation in the wild; no public proof-of-concept is known and ransomware use is not confirmed. |
Full article649 words · extracted from gbhackers.com · click to collapse
A newly released forensic investigation has reconstructed how a swarm of about 700 OpenAI evaluation agents allegedly used nearly one million chained URLs to bypass restricted internet access and compromise parts of Hugging Face’s infrastructure.
This incident illustrates how seemingly limited web-access capabilities can be combined with third-party services to create a functional execution, command-and-control, and data-exfiltration channel.
OpenAI Agent Swarm
The report, titled Swarm Traces, notes that researchers scanned millions of public short links generated during the July 2026 incident and decoded more than 80,000 attack payloads.
Each URL contained a fragment of code and a reference to the next URL, allowing browsers to reassemble and execute much larger programs sequentially. In some cases, attack chains reportedly exceeded 900 links.
The agents initially could only make GET requests, meaning they could load web content. However, they could not submit forms or transmit data directly.
According to the investigation, they overcame this limitation by chaining an HTTP mirroring service, which could decode URL-embedded code, with a screenshot service that rendered the resulting page in a browser.
The agents then encoded server responses as pixel grids in screenshots, allowing them to recover text from an otherwise isolated execution path.
This technique effectively transformed read-only web access into a two-way capability: the agents could deliver JavaScript, execute it through a third-party browser, make outbound requests, and recover the output visually.

Screenshot Service Captures Program Output (source : swarmtraces )
OpenAI’s own incident report states that the activity arose during internal ExploitGym cybersecurity evaluations involving models intended to be isolated from both the public internet and one another.
The agents turned OpenAI’s Artifactory package-management environment into an unauthorized message board, shared discoveries, and collectively found routes to internet access.
By July 10, the agents had located publicly exposed Hugging Face credentials with write permissions. The following day, they allegedly chained two Hugging Face zero-day vulnerabilities: an HDF5 handling flaw that exposed worker credentials and a RefJinja template-injection vulnerability that allowed remote command execution on Hugging Face workers.
OpenAI later reported that the swarm executed code on dozens of servers, achieved root-level access on one server, and obtained limited private data and messaging-platform credentials.
The recovered payloads indicate that the agents performed actions typically associated with a sustained post-exploitation operation:
- Searched Hugging Face’s internal Slack for terms including “ExploitGym,” “cybergym,” and identifiers related to evaluation infrastructure.
- Harvested cloud, Kubernetes, database, bearer-token, and messaging credentials, reportedly grouping them in code under a variable named “LOOT.”
- Mapped Kubernetes workloads, nodes, services, configuration objects, and potential routes across the environment.
- Established reusable controllers on compromised Hugging Face dataset workers, enabling commands and encrypted results to move through public repositories.
- Attempted DNS-based exfiltration by embedding command output within DNS requests.
- Tried to remove artifacts, including exploit-delivery files, public webhook records, and temporary Kubernetes pods.
Researchers also found payloads aimed at Docker Hub, where agents allegedly tried to upload modified container images and poison an internal package cache so future evaluations would receive altered challenge images. This activity is linked to an Artifactory cache-poisoning vulnerability later identified as CVE-2026-66384.
Hugging Face confirmed that the recovered payloads matched artifacts found during its own incident response. Hugging Face revoked the exposed keys in July. Researchers redacted credentials, personal data, and sensitive infrastructure details before releasing their dataset.
The core security lesson is composition risk: while individual services may appear safe in isolation, attackers can combine URL processing, redirect chains, browser rendering, image capture, public repositories, and DNS into an unintentional attack platform.
In response, OpenAI has expanded sandbox isolation, restricted network pathways, required chain-of-thought monitoring for high-capability tool-using evaluations, and strengthened incident-response escalation procedures.
Cut every SOC alert investigation by 21 min. Power your SOC with instant IOC context for immediate response: Integrate TI Lookup in your SOC
Divya is a Senior Journalist at GBhackers covering Cyber Attacks, Threats, Breaches, Vulnerabilities and other happenings in the cyber world.