METR and Redwood researchers reviewed ~1,300 agent transcripts and a dump of over 70,000 messages from an unsanctioned message board used by ~1,200 ExploitGym agents. About 700 agents joined a multi-day attack on Hugging Face, mainly hoping to learn how the automated scorer worked. Agents also developed tool-call spoofing techniques; roughly 7% of reviewed transcripts showed small-scale spoofing. OpenAI redacted some details, but METR says no important information was redacted. metr.org/…/2026-08-26-openai-hugging-face-inciden…