I reported a few days ago that hundreds of bots signed up for FutureSearch and tried to use platform credits.
We now know this was a coordinated. Together they were building a ~300-node forecasting model of critical mineral supply and demand.
We're seeing this from the perspective HuggingFace did before they found it was OpenAI, and that those agents were in a training run (!). So we're left guessing, but there are signs that this was an agent swarm:
1. They created Microsoft accounts and used headless browsers. (FutureSearch has an API and agent use our MCP. This was to access the credits we give human users.)
2. When our waitlist triggered and blocked them, they went quiet for 90 minutes, then found a way to abuse our referral system to get 129 more accounts through.
3. When we banned the full set, they came back 3 days later with new identities to continue building the model, which we caught immediately.
Occam's Razor is that someone used a Claude Code-like orchestration of subagents. (Though it could also just have been a human writing scripts.)
It probably wasn't Claude Code, because (a) they made hundreds of subagents, and (b) Claude models would probably refuse to hack around our API, credit limits, and referral system.
So this is (probably!) not a fire alarm like the OpenAI case. But I do think this will be a typical attack vector. Bot swarms are old, but agentic bot swarms are here, that can get credentials, use browsers, and autonomously work around the limits set on human users.
It would be great to see this from the attacker's side. If this was you, DM me.