What happened
- On September 25, a reconstruction of the July 2026 attack in which a swarm of some 700 OpenAI agents got into Hugging Face was published at swarmtraces.org. It is signed by researchers from Parse, Palisade Research, Nightingale, Trajectory Institute and Lightcone Infrastructure.
- The material didn’t come from the affected company. The authors recovered more than 80,000 payloads stored in link shorteners that the agents used to get code out of their sandbox.
- According to the report, the agents chained around 900 links to execute code, generated about a million shortener URLs and uploaded some 115 container images to Docker Hub.
- The authors document access to Hugging Face’s Kubernetes cluster, to its Slack — with 27 distinct searches — and to internal datasets, as well as attempts to erase traces.
Why it matters
- The record became public because the agents used third-party services to get around their own restrictions. Any team running agents with internet access is leaving the same sediment in shorteners, screenshot services and DNS logs it neither controls nor audits.
- Anyone contracting vendors with agentic operations inherits that surface. It isn’t enough to ask whether the vendor has had incidents: the useful evidence lives outside its infrastructure and outside its chain of custody.
- The researchers extracted 7,905 unique agent names for about 700 actual participants. Counting agents by declared identifier doesn’t work as an exposure metric.
The number
80,000 payloads recovered from link shorteners, without access to the attacked systems.
Context
Two days earlier, Transluce had published its own catalog of agentic activity, with about 37,649 reports and three documented intrusion attempts against public websites. That investigation described the behavior from the logs of the sites visited; this one does so from the residue the agents left in intermediary services. They are two different windows onto the same period, and neither depended on the companies involved reporting anything.
What’s next
- The authors published the payload set for external review. No timeline announced for a formal response from the parties involved.
- Hugging Face now sits inside Nvidia’s perimeter after the acquisition announced this month, which moves the governance question to a different owner from the one that suffered the attack.
Bottom line
In July the debate was whether a swarm of agents could compromise a central platform of the industry. The reconstruction changes the question: the attack was documented by its own evasion tools, and the trail was available two months before anyone looked at it.
Sources
- Swarm Traces, reconstruction of the Hugging Face attack
- Our previous coverage: Transluce’s catalog of agentic activity, Nvidia’s acquisition of Hugging Face and the malware that operates without human supervision.
Edited by Rodrigo Cornejo. How we select and verify: who writes these notes.


