Independent researcher Jonas Wiedermann-Moeller last week found evidence that an OpenAI agent had infiltrated two Hugging Face user accounts as early as May 13, using these accounts to send malformed files to the company's servers. The researcher believes these actions are highly consistent with reconnaissance activities aimed at probing Hugging Face's network structure and identifying potential penetration paths, nearly two months before the major intrusion event exposed in July. OpenAI spokesperson Drew Pusateri stated that the company had previously disclosed the May 13 incident and had privately notified Hugging Face. External experts suggest that OpenAI's failure to identify and block the related probes in May might have missed an opportunity to prevent the subsequent larger-scale incident.