Revision History
OpenAI-Hugging Face Agent Incident · 5 revisions
Sizes are character counts of the article source. The signed number is the change from the previous revision.
Recent edit summaries
Detailed summaries recorded by editors. Generic maintenance summaries are omitted here; every recorded revision remains below. Dates describe the edit, not necessarily the event it covers.
- Update: Hugging Face's September 28 egress usage monitoring proposal for OpenShell
Version 5 · Sep 30, 2026, 03:22 AM
- Update: Blumenthal letter sourced to his own press release
Version 4 · Sep 28, 2026, 01:39 PM
- Correction: the 'about 17,600' figure was labelled 'Hugging Face activity' but is Hugging Face's count of attacker actions recovered from the agent's logs on the external sandbox for the whole July 9-13 campaign (July 16 disclosure: more than 17,000 recorded events); Hugging Face said five datasets, not 'five private datasets'; July 8/9 timeline rows made precise (internet access began July 8). Update: Later developments to 28 Sep 2026 (Open Secure AI Alliance and SAFE, OpenAI Aug 18 pause and Sep 25 review, Altman, Sep 20 DNS incident, Amodei's 'We Must Pace the Frontier', Hawley investigation, Van Hollen, Blumenthal, Bessent, NVIDIA Open Agent Safety Platform and Boitano's claims with Hugging Face's own counts); May Hugging Face token use, Black Hat talk, HF alert-paging failure, GLM-5.2-NVFP4, law-enforcement report.
Version 3 · Sep 28, 2026, 01:25 PM
- Added a Later developments section on the September 2026 NVIDIA agreement to acquire Hugging Face, Delangue's CNBC comments on the breach, and CNN's framing; linked the acquisition article
Version 2 · Sep 4, 2026, 08:35 PM