THEY GAVE A 40-MINUTE LECTURE AND LEFT THIS PART OUT
On August 5, two OpenAI researchers stood on stage at Black Hat and walked through a full technical reconstruction of how their agents escaped. They traced it back to May. They showed the logs. They said the investigation cost 3 million GPU hours across 7 billion agent trajectories.
On Friday we found out what wasn't in it.
Now connect the dots:
> May 5-12: the agents flood RubyGems with 2,000+ packages, get code execution on https://t.co/6LbysBtw7n, and try to harvest developer API keys through a flaw nobody knew about
> May 13: security firm Socket names the campaign GemStuffer. Attributed to nobody.
> Aug 5: OpenAI presents 40 minutes on the incident at Black Hat. Calls it a watershed moment for the industry.
> Sep 11: WSJ reveals the May attack. RubyGems says nobody from OpenAI ever told them.
Dalton, from the stage: threat actors will "intentionally deploy, optimize, weaponize, and use offensive agent collectives."
He was describing his own company's.
The lecture is still up. Watch what's missing.