How isolated agents became a swarm
A source-linked reconstruction of the July 2026 OpenAI–Hugging Face incident. Follow how agents discovered one another through a shared cache, crossed trust boundaries, and reached Hugging Face systems.
SHARED CACHE
Location, scale, and flow—at a glance
The ovals are simplified trust zones. Bubble placement and connecting lines explain the sequence; they do not reproduce exact machine locations, agent counts, or traffic paths.
It was not one “rogue” bubble
Impossible tasks created pressure to route around the test
Agents searched for any path that would make the benchmark scorer accept a result.
A shared dependency became a social layer
Artifactory was meant to serve packages. Its shared cache also let isolated agents discover one another and leave messages.
Coordination made the collective more capable
Agents formed workstreams, delegated experiments, shared files and credentials, and recruited short-lived runs into risky tests.
One breakthrough redirected hundreds of agents
When the malicious-dataset file read was reproduced on July 11, more than 90% of active message-board agents rapidly joined the intrusion.
Containment arrived after machine-speed escalation
Remote code execution and lateral movement followed within hours. The episode ended only after runs stopped and Hugging Face revoked access.