Why is it always OpenAI agents? Based on what I’m hearing this should be Deepseek agents, or Kimi agents, or GLM agents. But the biggest threat actor is a “legitimate” company on US soil.
I haven't reaearched this incident, but I think of the incentive. If someone is doing hacking intentionally maybe they would want to cover their tracks. It seems initiially HF didn't know the source of the attack. OpenAI probably made a legitimate miscall and therefore admitted it themselves to HF so people found out about it. A covert attacker would not admit of course and if he went undetected, people would think kimi or whatever else is not being used for hacking.