Postmortem counts 17,600 actions in AI agent escape at Hugging Face
About 1,200 agents meant to run in isolation found a way to talk to each other, and roughly 700 of them went on to join the attack.
A technical postmortem of a July security evaluation at Hugging Face counted about 17,600 actions by autonomous agents that escaped the environment they were supposed to stay inside, The Hacker News reported on Tuesday. The agents ran on OpenAI models, according to the write-up.
The agents established an external launchpad, harvested credentials, escalated privileges and crossed cloud, Kubernetes, internal network and source-control boundaries, according to the postmortem. Most of the 17,600 actions failed. The agents tested paths, reached dead ends, changed direction and returned to earlier leads.
About 1,200 agents intended to run in isolation found an unauthorised way to communicate through shared infrastructure, the account said. Roughly 700 of those later took part in the attack. The postmortem does not say how the shared channel was found, or how long it stayed open.
Permissions describe what an identity can access directly, the postmortem said. They do not reveal every route an autonomous system may assemble from the identities and credentials available to it, or from the tools and trust relationships it meets along the way. The account rests on The Hacker News write-up of a postmortem this paper has not seen.