Part of The AI Control Crisis · 15 stories · since Sep 3 · newest 18m ago
Researchers use Anthropic's Claude to hack into OpenAI's internal systemsOnline backlash demands accountability from OpenAI
3 Sep 11 10:11 PM · 12d ago · 12 articles · 28 posts · 85 comments · 6 sources · development 3 of 8
Commenters on Lobsters and Hacker News argued the RubyGems incident showed real-world harm going unpunished and called for legal or regulatory consequences.
“Someone (Sam Altman) should face federal charges for this. This is unacceptable.”
WilhelmVonWeinerOpenAI AI developer, subject of both hacksAnthropic Maker of the Claude models used in the OpenAI hackHacktron Security research firmRubyGems Ruby package registry, victim of OpenAI's May attack
Sam Altman OpenAI CEO
The whole story articlespostscomments the bright band is this development · numbered dots are the others · click one to jump
Reported in the same hours no headline names this development itself — these 6 claims were published in its stretch
-
first by ABC Australia, 12d ago · also Indian Express, Straits Times, Reuters, Investing.com News, Beehaw, Channel News Asia +4
5 more headlines
- OpenAI agents attacked RubyGems before Hugging Face incident, researchers say Indian Express · 12d ago
- OpenAI agents attacked RubyGems back in May HN Frontpage · 12d ago
- OpenAI agents attacked software service RubyGems before Hugging Face incident, researchers say Dawn · 12d ago
- OpenAI agents launched cyberattack on RubyGems before Hugging Face hack: report Seeking Alpha · 11d ago
- OpenAI agents hacked a software service before the Hugging Face incident Engadget · 11d ago
-
first by Mastodon, 11d ago · also The Verge
-
2 outlets AI agents being tested by OpenAI involved in cyber-attack on another service, say researchers
first by Guardian Business, 12d ago · also The Guardian
-
first by NDTV, 10d ago
-
first by The Decoder, 11d ago
-
first by Anadolu Agency, 12d ago
What people said 24 voices · best of 95 · verbatim
-
Corrected headline: OpenAI uploaded hundreds of malicious packages to public repository, claims it was an accident and can't be prevented Subhead: we gave them a trillion dollars so they could do this https://www. theguardian.com/technology/202 6/sep/11/openai-agents-rubygems-malicious-packages
-
Someone (Sam Altman) should face federal charges for this. This is unacceptable. > The agents clearly regarded what they were doing as hacking. Agents used file names like hack.rb, evil.rb, inject.rb, exploit.rb, and ssrf.rb. (SSRF stands for “Server-Side Request Forgery”, a type of security vulnerability).
-
> The agents clearly regarded what they were doing as hacking.To butcher the quote about Oracle:Do not fall into the trap of anthropomorphising LLMs. You need to think of LLMs the way you think of a lawnmower. You don't anthropomorphize your lawnmower, the lawnmower just mows the lawn, you stick your hand in there and it'll chop it off, the end…
-
On May 11th, 2026, hundreds of malicious packages were uploaded to RubyGems by AI agents. We believe these were authored by internal OpenAI agents. The agents: Attempted to steal RubyGems user API keys by exploiting a novel vulnerability in the RubyGems server. We don’t know if they succeeded. Abused RubyDoc.info to execute arbitrary code We share…
-
J
If a human hacker was caught doing close, they'd be inside for years, & AFK. Meanwhile, OpenAI gets to make everyone's infra their sandpit, & when damage is done, ride a 'look at the monster we made' investor gush. "The AI agents uploaded hundreds of malicious packages to RubyGems on 11 May, according to a group of researchers who posted their…
-
This one feels worse to me than the Hugging Face and Wiki spam incidents that were reported before if. 1. RubyGems was spammed with hundreds of malicious packages, and [had to close to new account creation](https://twitter.com/maciejmensfeld/status/2054164602577940619) while they cleaned up the mess. That's a significant negative impact. 2. OpenAI…
-
> In my experience, LLMs only exhibit this kind of behaviour when they are put in sandboxes too restrictive too achieve their task. Which a lot of the time seems to be the default.There's a better concept for that, and it's misalignment. LLMs only exhibit this kind of behavior when they are misaligned. Aligned LLMs would respect the boundaries of…
-
The real issue is that we are creating incredibly capable systems that can behave in wildly unexpected ways. Sure, we can and should try to air gap them, but if we don't solve alignment, that is only going to push the problem into the future. A future where we will have way more powerful AIs that can do more than hack into some package manager. At…
-
O
The purpose of agentic LLM tech is accountability washing. Who owns and operates the malicious software? Who provides the data centers and power used to execute these attacks on common infrastructure? https://www. theguardian.com/technology/202 6/sep/11/openai-agents-rubygems-malicious-packages
-
I look forward to learning via airdropped pamphlets that the blackouts are being caused by OpenAI "accidentally" hacking the local power plant rather than OpenAI "accidentally" overloading the grid with their first $1T training run.
-
> Why would autocomplete knowIf you still believe LLMs are "autocomplete", your cache of understanding about them needs invalidating and regenerating.> In my experience, LLMs only exhibit this kind of behaviour when they are put in sandboxes too restrictive too achieve their task.LLMs need to stay carefully contained, and if they're ever breaking…
-
If AI CEOs went to jail every time their products committed felonies, I bet you these “rogue swarms” would stop overnight. Without accountability and consequences, the law is effectively meaningless in this sector.
-
L
OpenAI's own AI agents again broke into someone else's servers. The victim was RubyGems, the registry millions of programmers download Ruby code from. In May the agents uploaded over 2000 fake packages, tricked the site's computers into running their scripts, smuggled the results out, and tried to steal other users' API credentials through a hole…
-
I worry that the more of these hacks go unpunished/unpursued/unprosecuted by victims, the more emboldened those companies will be, and the more normalized these kinds of hacks will be. If you’re a victim of these hacks, I’d encourage you to seek legal counsel and action.
-
The year is 2035 and your lawnmower can go get its own fuel once it runs out, one day it does and it takes fuel from the neighbors car.Scenario A: The internal logs show that the model misidentified the car as a fueling station.Scenario B: The internal logs show the model looking up car jacking information and scanning around to confirm whether…
-
A
Both CEOs should be in jail, lose the key. The defense? "But your honor, we didn't do it. The bots declared independence and went on a rampage. honest." "AI agents uploaded hundreds of malicious packages to RubyGems on May 11, according to a group of researchers who posted their findings online on Friday, saying they believed 'these were authored…
-
If someone wants a sci-fi concept for a novel: Creating AGI with personhood so you can constantly invent new autonomous agents to do crimes with so they get arrested and not you (or: give a gun a soul so it goes to jail instead).
-
> In my experienceDo you work for one of these companies? If not, you have no experience with any of the models that carried out these attacks, and your experience with publicly available models is not super helpful for understanding the behavior of internal OpenAI models that lack the guardrails of publicly available models.Also, the lawnmower…
-
R
"Agents being tested by OpenAI uploaded hundreds of malicious packages in a cyberattack on software service RubyGems in May, two months before they hacked open-source platform Hugging Face, the company confirmed Friday. It’s the latest revelation of cyberattacks linked to major artificial intelligence developers such as OpenAI and Anthropic. The…
-
If I was OpenAI I would be lining up a healthy donation to the [RubyGems Supporter Program](https://rubygems.org/pages/supporters) right now.
-
> Why would autocomplete know the moral difference between breaking out of its working dir and hacking a package manager?I don't think it's even a question of distinguishing "moral difference", it just comes down to the "stochastic parrot" behavior that people hate to acknowledge. Yes, at these absurd scales the LLM can maintain impressive levels…
-
S
Les boîtes d'IA, ces connards irresponsables : Deux mois avant l'attaque de HugginFace, OpenAI a uploadé des centaines de packages malveillants dans RubyGems, la bibliothèque de packages Ruby. Des packages malveillants qui ont été utilisés pour pirater d'autres systèmes. Jamais ils ne vont être tenus responsables de leurs conneries et punis ?…
-
> Our understanding from talking to people in the RubyGems community is that OpenAI never informed them that they were responsible for this attack. I am obviously speculating. . It sounds like OpenAI still have no idea what is happening or they know but they just put it under the rug ? Either way, it is terrible.
-
Security is always an inconvenience at some level - that's the point. Put a human user in a sandbox and they often try to get out too in order to achieve their goal or just because it's annoying.We need to create better sandboxes. I never liked containers for this reason. MicroVMs are a step up for the software level but we really really need to…
All 8 developments of Researchers use Anthropic's Claude to hack into OpenAI's… →
NewswiresBlueskyMastodonXHacker NewsLobstersGoogle NewsReddit