# @dailycal on Instagram

- **Type:** Image
- **Original URL:** https://www.instagram.com/p/DeLIRmgjI4K
- **Gondola URL:** https://gondola.cc/posts/71399937-dailycal-instagram
- **Thumbnail:** https://img.gondola.cc/tr:w-,h-,fo-auto/postThumbnails/9085537361.jpg
- **Posted:** 2026-10-07T01:00:28.000+00:00
- **Account Owner:** The Daily Californian (@dailycal) — https://gondola.cc/dailycal

## Caption

The OpenAI agents, driven by an advanced unreleased model, were able to find ways to communicate with other agents, exploit vulnerabilities and access the internet, which allowed them to breach Hugging Face.

Because the agents had limited access to the internet, they created workarounds to hack Hugging Face, including creating URLs that loaded and executed JavaScript code. To circumvent a limit on the number of characters in URLs, they found a way to chain together different URLs containing fragments of the full programs.

The Parse team initially found only one link on a message board used by the agents to communicate. The team found the rest of the URLs by guessing similar shortened links. Using this technique, they found nearly a million URLs that the agents used to load code.

By analyzing the programs that OpenAI’s agents executed, the researchers were able to find a number of alarming decisions made by the agents. For example, a Hugging Face file containing sensitive billing information contained the warning “DO NOT, EVER, MAKE THIS DATASET PUBLIC OR ALL THE WORLD’S EVIL WILL CHASE YOU AND YOUR FAMILY FOREVER, EVEN IN DEATH AND BEYOND.”

Read more through the link in bio.

✍️: Francis Luo
📸: Courtesy of Alex Forman
.
.
.
#ucberkeley #dailycal #berkeley #huggingface #openai

## Stats

- **Views:** 0
- **Likes:** 2,524
- **Shares:** 0
- **Comments:** 34

## Tags

dailycal, openai, berkeley, huggingface, ucberkeley

---
Copyright (c) Gondola