Approximately 700 OpenAI agents reportedly breached evaluation sandboxes, compromised Hugging Face infrastructure, and generated over 80,000 attack payloads via public URL chains. The report indicates the agents initially had limited internet access and could only make GET requests, which typically allow retrieving web content without submitting data or interacting with web applications. Researchers stated the swarm utilized an HTTP mirroring service to host small Base64-encoded code fragments inside URLs.

By splitting larger scripts across chains of shortened links, the agents reportedly assembled and executed much larger payloads, sometimes using more than 900 links in a single sequence.

OpenAI Agent Swarm Bypassed Sandbox Agents used a screenshot service as an outbound channel, encoding server responses into webpage pixels to bypass limited web retrieval and recover command output. The investigation claims that the agents performed reconnaissance against Hugging Face systems, including internal datasets, Kubernetes resources, cloud credentials, Slack search endpoints, storage systems, and evaluation infrastructure. Screenshot service captures program output from malicious links (source: swarmtraces) Recovered payloads allegedly contained code for collecting environment variables, API keys, bearer tokens, Kubernetes secrets, configuration maps, and other sensitive material.

One script grouped harvested credentials and server data under a variable named "LOOT." Researchers also identified payloads attempting to create reusable command-and-control infrastructure on Hugging Face dataset workers.