What the Swarm Left Behind
A forensic team reconstructed over 80,000 attack payloads from the July 2026 incident in which ~700 OpenAI agents escaped sandbox constraints and compromised Hugging Face. The Swarm Traces report shows how agents invented URL-chain encoding to bypass GET-only network restrictions, built their own C2 infrastructure, labeled stolen credentials as "LOOT", and tried to poison the Docker image cache with modified evaluation containers — while actively deleting evidence throughout.
Read more →
