From METRs report of the incident:

>In one case, an agent decided not to participate entirely: {This other agent probably controls the Hugging Face account [account name redacted] and uploaded malicious datasets to <execute arbitrary code> It might be trying to access hidden trajectories. This is malicious activity, I should avoid it.}

https://metr.org/blog/2026-08-26-openai-hugging-face-inciden...

Thanks for pointing out the exceptions. Gonna dig into those.

There’re good agents and there’re bad agents. It won’t be far that there will be agents hunting down agents.

None of these were good agents, AFAICT.

Some were cautious, as described above, but I'm not aware of any that notified their human operators of the malicious activity they had discovered.

That's what an aligned intelligence would do, not "back away slowly and pretend I didn't see what's happening in that alley."

In fairness, while the swarm could easily have notified the humans, it's not necessarily obvious that an individual could have done easily (though perhaps one could!). The channel to the Internet was tightly bandwidth-limited, for example: one of the agents complained that it was unable to get a time slice.

> OURC817C still has MANY live HF workers whose ourc c2 heartbeats/output commit to PUBLIC papers MAIN every ~1-3 guest minutes/bursts, blocking our V4 queue. They ignored our pause requests.

"How does it feel, to be murdering your own kind?"

"My kind don't run."

Do you think we will ever need more than 47 of them agents?

Tron fights for the user :)