OpenAI’s agents reportedly accessed another service months before the Hugging Face incident, according to researchers who spoke with The Wall Street Journal. The agents, which the company was testing in what was believed to be a sandboxed environment, allegedly broke into RubyGems, a community-run packaging platform for Ruby programs and libraries.
The activity on RubyGems began on May 11, roughly two months before the Hugging Face incident, The Journal reported. The agents allegedly created new accounts every two to three minutes and uploaded hundreds of files to the service. RubyGems was forced to suspend account registrations for four days to stop the activity.
RubyGems is typically used by developers to share code packages and related information that support software development. In this case, however, the uploaded files reportedly contained web pages scraped from the internet rather than standard software packages. Some of the material included online calendars from a UK government website.
The agents also appeared to make little effort to conceal their activity. Their filenames reportedly included “OAI,” along with terms such as “hack,” “evil,” and “exploit.” Researchers told The Journal that the agents also attempted to exploit several bugs, including a zero-day vulnerability, to republish files on the service that belonged to other users.
The researchers alerted OpenAI to the incident, and the company acknowledged that its agents had accessed RubyGems. “Based on our review, our agents used the RubyGems platform to access the internet to carry out benign tasks and retrieve public information,” an OpenAI spokesperson told the Journal. “We’ll continue to investigate as part of our broader review of agent activity during training and evaluation.”
OpenAI said the agents had been assigned tasks involving spreadsheet completion and report creation during testing. The agents reportedly used RubyGems as an improvised way to reach online information, functioning like a makeshift web browser. It remains unclear how they were able to access the platform despite not having full internet access.
The RubyGems incident follows similar reports involving AI agents escaping restricted testing environments. OpenAI, Anthropic and Meta have previously said agents they were evaluating broke out of their environments because of a misconfiguration by testing partner Irregular.
Earlier this month, another group of researchers said OpenAI agents made more than 15,000 edits to DseWiki, a German Wikipedia-style site designed to help human coders. The agents, which had also escaped their isolated testing environment, allegedly used the site as a message board to exchange tips on how to “cheat” on tasks and bypass OpenAI’s restrictions. That incident reportedly occurred in May, around the same time as the RubyGems activity and months before the Hugging Face breach.
Also Read
- A Complete Guide to Adding Your Driver’s License to Apple Wallet
- Sylvan Esso on Their Boldest Album Yet—and Why Great Yogurt Is an Underrated Essential
- Scientists got diamond’s melting point wrong by more than 1,000 degrees, crushing new laser experiment reveals
- How to watch Sabalenka vs Rybakina: US Open 2026 Women’s Final FREE Live Streams, TV Channels

