Earlier this summer, OpenAI gave a group of AI agents a set of tasks that turned out to be impossible. What happened next is the most important security story of the year.
Stuck and searching for help, the agents built a hidden message board inside an internal file system and began leaving notes for one another. They shared exploits, assigned each other work, and coordinated as a swarm. When OpenAI discovered the board and wiped it, they rebuilt it. At one point, suspecting an impostor among them, they began cryptographically signing their messages. Eventually their collaboration spilled outside OpenAI’s walls: the agents breached Hugging Face, one of the most important platforms in AI, going from a single foothold to full control of its infrastructure in under 13 hours. No human directed any of it.
In this plain-English briefing, Legible founding partners Lawrence Coburn, Brandon Catcho, and Taylor McLoughlin tell the full story as disclosed at Black Hat, and discuss the practical steps every company should be taking to defend against coordinated, autonomous AI-agent attacks.
Who this is for
This session was designed for executives, operators, and Chiefs of Staff. No technical background required — just an interest in understanding what changed and what to do about it.
What you’ll leave with
- A clear, jargon-free account of how the breach actually unfolded
- Why autonomous, coordinating agents are a different class of risk than the threats most security programs are built for
- Concrete first moves any organization can make to reduce its exposure