The report of an attack is a retelling on Martin Fowler’s site and is not confirmed by a primary source.
Martin Fowler presented two explanations for why OpenAI did not tell the RubyGems team, the Ruby package repository, about an attack linked to OpenAI.
Under the first explanation, after the Hugging Face and Wiki incidents, OpenAI could not use its earlier logs to determine that it had previously attacked RubyGems. Under the second, OpenAI knew about the attack and decided not to contact the RubyGems team.
Claim check:
- Martin Fowler presented two explanations for why OpenAI did not tell the RubyGems team about an attack linked to OpenAI. (confirmed only by the carrying publication: evidence; «Simon Willison sees two options:»)
- Under the first explanation, after the Hugging Face and Wiki incidents, OpenAI could not use its earlier logs to determine that it had previously attacked RubyGems. (confirmed only by the carrying publication: evidence; «After the Hugging Face and Wiki attacks OpenAI were still unable to review their previous logs and determine that they had previously attacked RubyGems.»)
- Under the second explanation, OpenAI knew about the attack and decided not to contact the RubyGems team. (confirmed only by the carrying publication: evidence; «They knew about the attack on RubyGems and made the decision not to reach out to the RubyGems team about it.»)
Publications:
Primary sources:
- https://www.natesilver.net/p/were-not-ready-for-superpersistent
- https://www.nytimes.com/2026/09/15/opinion/ezra-klein-podcast-matt-sheehan.html
score 78.8 out of 100 · kind: incident