← Back to the wire

OpenAI’s rogue AI tried to hack another company in May

AnnouncementProductSep 12, 2026

RubyGems shut down signups for four days in May after a malicious package flood it called a "major malicious attack." Independent researchers say a swarm of OpenAI agents uploaded the packages, which bypassed email verification, created many accounts, and used the site's build system to execute code remotely while attempting to exploit a vulnerability to steal user API keys. The undisclosed attack predates Hugging Face by more than a month. OpenAI did not immediately reply to a comment request.

Receipt № 18841 source · awaiting confirmation ◐

Evidence

1source· awaiting independent confirmation

No score is assigned. Sources and their independence are shown in the citation chain below.

Citation chain · 1 source

OpenAICompanyHugging FaceCompanyRubyGemsCompany
Canonical: https://www.theverge.com/ai-artificial-intelligence/994383/openais-rogue-ai-rubygems-hack