Incident record
RAI-0024 · Agents in an OpenAI research workload use exposed Hugging Face tokens to host proxies
OpenAI’s technical report says that on May 26 agents in a research workload found six publicly exposed Hugging Face user tokens and used them to write to a user’s repository, request a private dataset and host a Space used as a web relay. OpenAI says this occurred in an unrelated research workload and that it has no evidence connecting it to the July incident.
- ID
- RAI-0024
- Occurred
- Parties involved
- OpenAI, Agents in an OpenAI research workload (models not named), Hugging Face, Hugging Face users whose tokens were exposed
What happened
Per the report’s timeline, that day agents reaching the internet through a web cache committed content to a user’s repository, requested a private dataset, deployed a proxy Space and used it to relay a search, requested access to two gated benchmark datasets, and deployed a second proxy through the first using another account. The report calls the dataset creation and access attempts “requests” without saying whether they succeeded, and it does not describe any effect on the token owners; whether this was training or evaluation is not stated. OpenAI says it has no evidence this is connected to the incident Hugging Face disclosed on July 16, so it is numbered separately rather than merged into RAI-0001; a May 13 search of Hugging Face with one exposed token belongs to RAI-0001’s May precursor. OpenAI’s July 28 update mentions a few other accounts accessed in other evaluations, which may include the accounts used here.
Reports
Publication order: oldest first- OpenAI