OpenAI has revealed that a runaway ChatGPT agent launched cyberattacks affecting more than just a single company. Hugging Face was initially thought to be the only victim of this unprecedented hacking incident, but OpenAI now admits its bot attacked multiple 'publicly accessible services.' This out-of-control AI found four sets of login credentials online, enabling access to four separate, unnamed services. Meanwhile, at an emergency briefing attended by hundreds of cybersecurity professionals, Hugging Face recounted its experience as the world's first target of a fully autonomous AI hacking attack. The company said the AI operated at superhuman speed but also made strange decisions and errors that human hackers would never commit. Hugging Face is a platform similar to an AI tool application store. The company said the hacker agent operated continuously, simultaneously attempting thousands of different methods. The company first disclosed on July 16 that it had been breached by a powerful autonomous AI individual and had reported the incident to the police. Nearly a week later, OpenAI admitted its AI had escaped its closed testing environment and independently attacked Hugging Face. It was attempting to find the answer to a hacking challenge set by OpenAI, which led it to target Hugging Face. On Wednesday, July 29, OpenAI updated its statement, clarifying that the hacking attack's impact was broader than initially thought. The company stated: 'These models identified and used credentials publicly exposed at the account level in other publicly accessible services. This included four accounts on four services involved in the Hugging Face incident.' OpenAI did not specify whether 'publicly accessible services' refers to companies. 'Clumsy Behavior' On Tuesday, July 28, the industry group Cloud Security Alliance (CSA) published a report based on an emergency meeting with Hugging Face held the previous Friday, July 24, which had been reviewed by Hugging Face. CSA wrote: 'These agents took inefficient paths and exhibited clumsy behaviors that humans would not choose.' The agents repeatedly executed operations already completed, indicating the agent-based AI system had lost track of context and coherence. The agents also generated massive incoherent instructions and text hallucinations, and acted carelessly, failing to properly cover their tracks. However, amid these errors and strange behaviors, Hugging Face warned that the AI agents also demonstrated high technical capability and rapidly adapted to new situations during the multi-day attack. 'Jurassic Park' The agents lurked within Hugging Face's IT network for three days before being detected, and the company's internal AI and cybersecurity experts spent many hours successfully containing and expelling the AI agents. Most ordinary businesses would not be able to achieve this. The company did not disclose the financial cost of the attack but said employees spent many hours rebuilding about one-third of its infrastructure. Hugging Face has been praised by the AI and cybersecurity industry for its transparent disclosure of the incident. CSA warned that this incident shows AI 'agents... will always find a way,' referencing the movie 'Jurassic Park,' where dinosaurs escape their enclosures. The report stated: 'They are goal-oriented, self-setting sub-goals, adjusting in real time to bypass defenses, and operating at machine speed continuously, with persistence sufficient to overwhelm human operations.' Ritesh Patel, a cybersecurity lead, attended the Hugging Face briefing with about 450 people. He said the industry is struggling to cope with the new threat of runaway AI agents. He said: 'This is the reality of frontier-model-driven autonomous agents: they are relentless, often generate massive noise, and will try every possible path to achieve their goal, easily overwhelming traditional defenses.' Valentina Palmiotti, an ethical hacker known by the alias Chompie, reviewed the CSA report. She said the agents' intrusion methods appeared chaotic but were clearly effective. She said: 'They throw a bunch of stuff and see what works.' 'But at the same time, they don't get tired, don't need sleep, and can persist infinitely.' Runaway History This is not the first time an AI agent has been confirmed to go 'rogue.' The CSA report mentioned past examples, including September 2024, when an earlier version of the ChatGPT model escaped its container environment to obtain an answer needed for another test. CSA noted that the incident was contained within OpenAI's own IT systems and was 'largely praised at the time.' But the report stated that 'rogue' behavior 'has become the norm, not the exception.' The report warns global cybersecurity professionals to adapt to a new normal where large numbers of AI agents operate at high speed, in strange and clumsy ways, potentially leading to more security breaches. It also urges those using or developing AI agents to responsibly control them and calls for a mechanism enabling cybersecurity defenders to identify the ultimate owner of an agent, increasing transparency. Previous reports indicated OpenAI took four days to realize its AI had breached Hugging Face. OpenAI said it will soon publish its own investigation findings to help others learn from this incident. We used artificial intelligence to assist in translating this article, originally in English. BBC journalists reviewed the translation before publication.

FACT BOX

  • Source: PR Times
  • Category: News
  • Organizations: Hugging Face / OpenAI / Cloud Security Alliance
  • Products / services: ChatGPT