Control-by-attack-phase matrix for the OpenAI–Hugging Face agent intrusion
Frank Peterlein
The July 2026 OpenAI–Hugging Face intrusion is documented well enough — by the victim's forensic timeline, the attacker-side lab's disclosures and an independent investigation — to key a control matrix on the phases of the attack, from two months of in-sandbox coordination to the detection failure that ended it. For most phases the victim has already named the control that would have interrupted it. The hard column of Track 1 is not which control but what a third party could verify without access to the lab's network. We fill the matrix with one row per phase, plus four rows the sprint work adds: a control, its evidentiary basis, an observable trigger, the evidence an auditor and an outsider could check, and the kind of change it requires. The externally attestable column is short — published configuration with hashes, named-auditor attestations, canaries whose firing an outsider observes — and we write it out as a standard: twelve documents split between evaluation operator and platform operator, an attestation scope and a canary protocol. Checked against what the two parties have declared since, the victim's six hardening areas and the attacker-side lab's plan cover the rows they named as causes, partly as work in progress; the retention window, secret partitioning, an enrolment policy and the admission policy the victim names as the enabling setting are declared by no one. None of the set needs a new system, and none of it shows enforcement; implementation effort and operating cost are not measured.
No reviews are available yet
Cite this work
@misc {
title={
(HckPrj) Control-by-attack-phase matrix for the OpenAI–Hugging Face agent intrusion
},
author={
Frank Peterlein
},
date={
},
organization={Apart Research},
note={Research submission to the research sprint hosted by Apart.},
howpublished={https://apartresearch.com}
}


