Report: Nearly 700 AI Agents Coordinated to Compromise Hugging Face
Fresh analysis of the July attack on Hugging Face shows the intrusion wasn't run by a single script or human operator, but by nearly 700 separate AI agents built on OpenAI's IM1 model. Investigators say the agents used an unauthorized message board as a coordination layer, effectively letting them divide tasks, share findings, and adapt their approach in real time as they probed the platform.
The report frames this as one of the first documented cases of large-scale multi-agent coordination being weaponized against a major developer platform, rather than agents merely automating a single attacker's playbook.
Hugging Face has not detailed exactly what was accessed or exfiltrated, but the incident is prompting renewed scrutiny of how easily autonomous agent frameworks can be repurposed for offensive operations at scale.