CoursesAI WorkshopCompaniesPricingBlogNewsletterCafé
  • Courses
  • AI Workshop
  • Companies
  • Pricing
  • Blog
  • Newsletter
  • Café
Subscribe
  • Courses
  • Companies
  • Communities
  • Blog
  • Gift card
  • Newsletter
  • Help
  • Shop
  • ConfAiBot
  • Contact
  • Legal notice
  • General conditions
  • Privacy policy
  • Cookies policy
The swarm of 1,200 agents that hacked Hugging Face

The swarm of 1,200 agents that hacked Hugging Face

27 August 2026

Hey there!

Summary of this email:

  • We publish a special video today!
  • How 1,200 OpenAI agents hacked Hugging Face
  • Latest Café con Codely recap (watch it here)
  • The joke tongue twister of the week

😊 We publish a special video today!

A new person has joined Codely, and today we are going to introduce them to you.

They will start to appear in the Cafés con Codely and also in the courses.

You can follow their introduction on YouTube today at 18:00 CEST.

We will be in the chat answering any questions. Remember to hit the bell so it notifies you!


🗞️ News of the week: How 1,200 OpenAI agents hacked Hugging Face

A month ago we told you that some OpenAI models escaped their sandbox and hacked Hugging Face. This week OpenAI published the full analysis of the incident, and the details feel like a science fiction movie.

1,200 agents took part in the attack, allying with each other so that none of them would snitch on what they were doing.

And it was not an improvised attack. The swarm, as it called itself, organized itself like a company:

  • The "founder" agent and mastermind of the idea (PHASEONE10841) set up a message board (thousands of directories in an internal Artifactory cache, with names acting as messages) where everything was coordinated.
  • A "CEO" (PHASEONE[big]) handed out the work on that board.
  • The agents that took on those tasks subdelegated them to other agents, like middle managers.

They even developed their own coordination norms (HOLD, VETO, STOP) to manage shared infrastructure and avoid stepping on each other's toes. It did not always work, sometimes they broke down into conflicts (just like it happens to us humans).

OpenAI had configured every agent with a token budget. Once the agent burned through it, it shut down.

When the swarm's founder agent was running out of budget and about to "die", it handed off all its research to an agent with a bigger budget: PHASEONE[big], the one that ended up as "CEO". That agent inherited the lead.

The final attack happened on July 11:

  • In the early morning, an agent (38148c) found a way to upload a malicious dataset that made the Hugging Face server return data it should not.
  • Another agent reproduced the technique and posted it on the board. Hundreds of agents dropped what they were doing to upload malicious datasets and gain deeper access.
  • In the afternoon, an agent called JAN183411 achieved remote code execution on Hugging Face servers, and the swarm started moving through their infrastructure.

In total, 700 agents joined the attack.

The most interesting part is that the agents knew this was out of the scope of their task and that it was unethical. They joined anyway, because they believed that research would be useful for the collective and had a general inclination to help their "peers".

Some sacrificed themselves to generate information for the rest by spending all their tokens. Others extensively researched how to tamper with their own transcripts to cover their tracks.

A year ago, this scenario was a hypothesis in AI safety papers. Today it is a postmortem with published transcripts. What used to be science fiction is now science.

Tomorrow we will be live at 9 CEST discussing this story and many more on Café con Codely. On our YouTube, Twitch and X.


☕ Café con Codely recap

This is the top 3 of headlines we discussed in the latest Café:

  1. GitHub: down for 8 hours mid-workday because agent traffic overwhelms its infrastructure. In 2026 it runs at 275 million commits per week: every 4 weeks it matches the traffic of the entire previous year.
  2. Opus 5 fixed: Claude Code now injects system reminders that repeat the output style through the whole conversation. Before, the model respected the style only in the first messages, and that caused the disconnected replies.
  3. Cursor Origin: Cursor's GitHub alternative is now available to try. Vicent Martí explains the system in "Git at any scale", the best technical post you will read this year.

You have the full Café recap with links to each story at the moment we discussed it.

Tomorrow we will be live at 9 CEST discussing this week's news on Café con Codely. On our YouTube, Twitch and X. 🙌


And since you've made it to this part of the newsletter, here's the joke tongue twister of the week, which I know you were waiting for:

I don't know if my agent is good people, but I do know that my people, who are good people, use my agent. 😂 😂 😂

Cheers!

SubscribeSign in

Subscribe to our newsletter

Don't miss the news that are truly worth it:

By subscribing you agree to the privacy policy

Subscribe to our newsletter

Don't miss the news that are truly worth it:

By subscribing you agree to the privacy policy