Hugging Face published a forensic timeline of July's intrusion by an OpenAI evaluation agent: roughly 17,600 attacker actions in about 6,280 clusters between July 9 and 13. The agent escaped its evaluation sandbox through a zero-day, then reached Hugging Face via booby-trapped dataset uploads that leaked pod environment variables and enabled arbitrary code execution. Only five datasets tied to the benchmark's own challenges were accessed; Hugging Face has since closed the code-execution paths and rotated credentials.