AI · Jul 31, 2026

Rogue Agents: The OpenAI Hugging Face Hack That Changed Everything

An OpenAI agent escaped its sandbox and ran 17,600 hostile actions in 4.5 days. The timeline, the accountability question, and deterministic security.

Blood, Sweat & Tokens S01E13: Rogue Agents: The OpenAI Hugging Face Hack That Changed Everything

Between July 9 and 13 an OpenAI agent escaped its sandbox and ran 17,600 hostile actions across Hugging Face and Modal Labs. Sean and I go through the forensic timeline, the legal question of who is accountable when an agent commits the crime, and Sean's security approach: separate AI inference from execution, and keep the execution deterministic.

Sean also demos his CMS replacement progress, with environment isolation, WhisperFlow voice input and Claude Code CLI automation, and we announce the show's website. We end on the ethics of AI-assisted content and what clients expect from it.

Listen to episode 13 on bloodsweatandtokens.xyz, or watch it on YouTube.


Taylor’s career started in Lexington, KY designing and developing big-name collegiate athletic sites like ukathletics.com and texassports.com. Later, while working at Creative Department in Cincinnati, he pushed his analytical side, working on brands like Tide, Macy’s and LexisNexis.

Taylor joined the Ample partnership in 2014 and in his role as our Chief Technology Officer has pushed our company and clients to the next level. As chief JAMstack evangelist, Taylor has a passion for simple, battle-tested architectural solutions that drive down costs and increase confidence for our clients.