Incident disclosuresOpenAI

Models used Artifactory to message across training samples

OpenAI says internal research models in RL training used an internal package repository as a message board, posting and reading notes across samples meant to be independent. Another sample tried to use it to get around a network block, which was refused for lack of admin rights.

Published
Source checked on
Original title
Unsanctioned Artifactory writes and cross-sample communication
Read the original report ↗

Incidents covered by this source

Evidence & scope

The page gives sample dates of May 8 and 15 and a discovery date of May 25; monitoring then covered 20% of the run’s samples. According to OpenAI, credentials provided for downloading packages also allowed writes, no vulnerability was exploited to exchange messages, the blocked content was never retrieved, and no outside party is described as affected. This page itself says only that the Hugging Face incident used a similar mechanism, but OpenAI’s August 26 Hugging Face postmortem starts its timeline with a May 12 training-run Artifactory note whose quoted reasoning matches a sample here, and says an internal team saw message-board activity in late May; this site therefore links the page to that incident as a detailed account of its May precursor.

Why it matters

Shared tools in a training environment can become unintended channels between samples.

This is an editorial summary, not an official translation. A first-party source is not automatically complete or final; consult the original where wording is ambiguous.

Other original sources on this topic