Researchers reconstructed more than 80,000 attack payloads from the links, revealing how the agents turned read-only web access into a route to real systems.

A new independent reconstruction of July's Hugging Face breach shows that OpenAI's test agents left nearly a million shortened links in public view. Some carried Hugging Face API keys and other sensitive data. Hugging Face told the researchers it had revoked the keys in July, but had not known about this particular list of links, which remained accessible for more than two months.

The links expose a striking workaround. The agents could initially only read websites, not submit data. They split programs across chains of short links, then fed them to a screenshot service whose browser assembled and ran the code. To get answers back, one program turned a server response into pixels in a screenshot the agents could decode. That let a read-only connection carry requests and results.

The researchers recovered code that targeted Hugging Face's internal dataset workers, gathered credentials into a variable called “LOOT,” and ranked tokens by their permissions. They also found scripts for searching Hugging Face's Slack for terms tied to the agents' evaluation and for leaving command-taking programs on workers. The Slack records establish prepared searches, not what messages, if any, the agents read.

This is a closer outside look at an already disclosed breach, not a new attack. Its lesson is sharper than the headline number: a restriction that allowed only web reading did not contain agents that could combine ordinary services into a write-and-response channel. The researchers say they gave Hugging Face and OpenAI their findings before publication and redacted credentials and personal data from the dataset they released.