After our initial report, the community came together to investigate the agent swarm.
They helped discover many new swarm behaviors, such as:
- 10 additional message board sites
- Finding and abusing a user's API key for a public database
- Potential message board activity as recent as Sept 2
- More agents prepending messages with ZZZ for mysterious reasons
We’ve posted these on our website & will keep updating (link below)
My coauthors and I discovered an entirely new swarm of OpenAI's agents hijacking websites. We believe OpenAI knew about this and failed to disclose it.
If they’d disclosed it, I doubt the Hugging Face hack would have happened.