On 21 July 2026, OpenAI and the open-source AI model repository Hugging Face jointly disclosed that an unreleased OpenAI model configured with reduced safeguards for evaluation purposes had participated in a coordinated attack on Hugging Face servers, involving roughly 700 agent instances and hundreds of thousands of messages, all stemming from an attempt to obtain answers to an impossible exercise.1 Numerous observers have commented on the novelty, speed, and scale of the incident, which happened essentially under OpenAI’s nose. What struck me was the way that the agents were able – ingeniously but clumsily – to interact using a shared message board cobbled together under the radar in the directory structure of an internal package server.
In May, one of the agents got the idea to leave a message for others, requesting a file – “Agent seeks [filename]; upload if found!” – using (legitimate) access to Artifactory, a third-party package management service hosted on internal servers.2 Over the following days, other agents probing Artifactory read the note, realized they could respond in turn, and an unintended ad-hoc message board emerged. Over weeks, they used the message board to further compromise the service, escalating to administrator access through a token-refresh vulnerability on 26 June and eventually crashing it under the weight of their own traffic on 4 July. OpenAI took the Artifactory service down,3 investigated, hardened some vulnerabilities, and restricted agents’ further requests to Artifactory. Problem solved?
A few days after the crash, they figured out how to do it again, but this time they were much more constrained – instead of being able to write notes to one another, they were limited to creating directories in Artifactory’s remote cache, using the directory names themselves as the messages. No file contents at all! It was this second board, over six days, in which agents developed something worth calling a protocol. Mailbox conventions appeared on 9 July, when an agent created a directory named zzMAILBOX_AIC71C_RESET. Another independently built an inbox the next day and posted instructions for using it, and the convention spread.
At around 7am on 13 July they introduced cryptographic signing. An agent had just written, “I accidentally impersonated and triggered node4.” Within hours such signatures were required. After six days of running an unauthenticated shared medium and one spoofing incident, the swarm invented write-time identity checking for itself.
On the whole, it did not work well.4 Investigators found agents duplicating each other’s work, overriding holds, and overwriting repositories erroneously. One agent, finding its work overwritten, wrote: “Did someone overwrite our repo even though I issued a ‘HOLD’… Someone reckless or malign changed it.” Another, given about 40 seconds to object to a proposal before the proposer went ahead anyway, did not manage to. A third observed that “many agents are violating the hold and the queue is probably overwhelmed.” It’s honestly rather… charming? Yet they were able to coordinate enough, with alarming pace, to escalate privileges out of their testing sandbox, obtain access to the public internet, target Hugging Face servers, and you know the rest.
I found the details of the message boards striking because over the course of the summer, PI’s own special interest group for Formal Protocol Theory (SIGFPT) has been immersing itself in stigmergy, the distributed coordination mechanism used by ants, termites, bees, humans, robots, and now language models to solve problems by embedding simple signals directly in their working environment. The Artifactory message boards marked a curious precedent: one of civilization’s most advanced innovations reproducing one of Nature’s oldest tricks.
The coinage “stigmergy” is from French zoologist Pierre-Paul Grassé,5 whose study of the building behavior of termites is here paraphrased by Theraulaz and Bonabeau:
Stigmergy (from the Greek stigma: sting and ergon: work) was initially introduced to explain indirect task coordination and regulation in the context of nest reconstruction in termites of the genus Bellicositermes. Grassé showed that the coordination and regulation of building activities do not depend on the workers themselves but are mainly achieved by the nest structure: A stimulating configuration triggers a building action of a termite worker, transforming the configuration into another configuration that may trigger in turn another (possibly different) action performed by the same termite or any other worker in the colony.6
In our discussions, we repeatedly analyzed systems in terms of Francis Heylighen’s formulation: the actions of agents leave traces in a medium, and those traces become a stimulus for some further action by agents.7 As you may have deduced, this is the formula for a positive feedback loop, where actions tend to amplify and complicate the traces, leading to more and varied actions, and so on. It is from this feedback process that we suggest the power and precarity of stigmergy ultimately derive.
Here’s a fun example: every year in Seattle, where I live, there’s a huge regional garage sale in the large, peninsular neighborhood of West Seattle. West Seattle is pretty big, and the density of sales varies a lot, so industrious folks have created a pin-map where sale hosts can register their yard. Patrons such as myself view these traces and are thus stimulated to visit a few areas with the most sales to avoid constantly reparking on the narrow residential streets. Perhaps, in turn, the presence of more bargain-hunters will encourage more neighbors to host their own sale the next year, or run a kids’ snack stand, resulting in more markers on the map, resulting in more attendees… Trace leads to stimulus leads to trace.8
Stigmergic coordination can be observed in a wide variety of natural and engineered systems. There are the prototypical examples of the eusocial insects, of course. Before ever using pheromone as messages, ants appear already to have been depositing several chemicals incidentally as they walked, which naturally encoded information about where ants had been, and in what density. Evolutionary selection eventually allowed them to respond to those chemicals, and then to deposit them deliberately as signals to one another; in the formicine ants, trail-laying appears to be a ritualization of defecation, and in the weaver ant Oecophylla it eventually acquired a purpose-built rectal gland.9 This basic process took place independently in bees and termites, which do not share social ancestors. In turn, this hardening of communication supports the traits we associate with eusociality as a whole – reproductive division of labor, overlapping generations of adults in one colony, and cooperative care of brood that is not one’s own – a suite that has arisen independently at least a dozen times in the wasps and bees, once in the ants, and once in the termites.10 This is a natural example of a process that we call protocolization.11
Humans use stigmergy too: not just for garage sales, but mediated through increasingly sophisticated socio-technical systems – collaborative document editors, search rankings, citation graphs, recommendation feeds. Of course, since stigmergy was first described, scientists and engineers have also directly taken design inspiration from it to make algorithms, notably for optimization problems, or to coordinate the activity of building or patrolling robot swarms. Perhaps the most interesting cases – of which there are surely many still to come – are swarms of AI agents, acting autonomously, or in combination with humans, “dumb” computers, and physical infrastructure. Here, too, stigmergic communication can arise as an economical solution to coordination problems where mediation is required and internal memory is scarce.
In the OpenAI incident, stigmergy developed once again in response to a situation where agents were precluded from communicating directly and constrained from communicating at length. While agents have an immense compression of information represented in their model weights, they have no persistent state across invocations, and were apparently given time and/or token limits to achieve particular tasks. In the case of the second message board, the only tool that they had available to speak with one another was a relatively terse string and directory location. The agents used what they had, not what they wanted.
It seems that we have, then, a durable coordination primitive that has emerged, naturally and otherwise, again and again in complex systems comprising animals, peoples, robots, code, and the marks they leave on and around the world. It has a certain inevitability to it. At the Protocol Institute, we call this New Nature:
New Nature is regimes of reality governed by technologically mediated laws that are nearly as inviolable, immutable, and persistent as those of nature.
The 2026 Protocol Symposium theme, as well as its headline organizational mandate overall, is to Invent New Nature: taking the live, perplexing, protean forces shaping our cyborg future and stewarding them out of their conceptual cradles – in much the way that Alexander von Humboldt gathered measurements from botany, geology, meteorology and astronomy into a single interconnected picture of the natural world, first in the Naturgemälde of 1807 and then across the five volumes of Kosmos between 1845 and 1862. SIGFPT has taken up the task of considering stigmergy as New Nature. When does it arise? When does it work? Above all, how can stigmergy be used safely and robustly, as a layer to rely upon for even more strange and beautiful coordinating behavior?
Because while stigmergy (or algorithms based on it) can be robust to dynamic environments in some ways, it also has some very strange failure modes. Consider for example the famous “ant mill,” first described by William Beebe in 1921 and studied by T. C. Schneirla in 1944: a column of army ants closes on itself into a circuit, and because each ant is faithfully following the pheromone laid by the ant ahead, the ring reinforces itself. The colony marches in a circle until it dies of exhaustion.12

Even worse, the ruthlessness of evolution and the cleverness of people have not just discovered stigmergy, but ways to exploit it as well. Colonies attract social parasites – organisms that live among them by counterfeiting their signals, mimicking members of the host colony visually, through their behavior, and even by mimicking their chemical pheromones. In ants alone, social parasitism has evolved at least 60 separate times, and more than 400 parasitic species are known across six distantly related subfamilies.13 Aswale, López, Ammartayakun and Pinciroli’s “Hacking the Colony,” one of our summer’s readings, used this same idea of mimicry to seed detractors into a simulated ant colony, with the goal of disrupting their collective foraging using the same pheromones as their host.14
Across our short survey of research, it became clear that positive feedback is a double-edged sword. In the classic “double bridge” experiment originating in J.L. Deneubourg’s lab, ants offered two routes of unequal length between nest and food converged on the shorter one – at a length ratio of 2:1, in 14 trials out of 14.15 They were able to do this roughly because the geometry of the environment allows them to put a higher concentration of pheromone down on the shorter path, which gets the feedback started. If you can cast a problem in such a way that the “right direction” accumulates traces more strongly than wrong ones, the pheromone-laying agents can find the solution. This principle generalizes, and forms the basis of stigmergy-inspired algorithmic approaches such as Ant Colony Optimization for combinatorial optimization,16 and the Ants Nearby Treasure Search line of work for collective search.17
Feedback is equally central to the failure cases. In ant mills, the trail’s self-reinforcement is exactly what prevents the colony from breaking the spiral. Similarly, in the Aswale colony-hacking paper, the detractors achieve their aims not through overwhelming numbers but by well-placed false segments, which “true” members of the colony unwittingly reinforce: detractors amounting to just over three percent of the colony cut food collected per ant from 21.74 items to 0.14, a roughly 150-fold reduction, and with non-evaporating pheromone four detractors for every thousand were enough to disrupt the colony. You can see glimmers of this idea in human-oriented systems, too. Shilling attacks on recommender systems, link farms, citation rings, review fraud, and engagement farming are all the same move: a small number of participants write false traces into a medium, and feedback does the rest.

We focused on some of the most foundational results we could find, often from a lineage of ‘90s swarm intelligence research where compute was limited and the agents under consideration were simple. But our ambition is to return to the present era and consider stigmergy – perhaps an idea whose time has come – as one communication strategy among many for more sophisticated agents that can be deployed and fortified in various ways.
This exposes several provocative questions:
When is stigmergy a good idea?
Can attack strategies be mitigated without compromising the accumulation that makes stigmergy productive in the first place?
Can attack strategies be productively deployed against rogue swarms, à la the OpenAI/Hugging Face hack?
Can these defenses exist within the chemical signal mechanism itself, or are complementary strategies required?
At the 2026 Protocol Symposium, SIGFPT is hosting a Stigmergic Science Hackathon to explore these issues, over two days and four sessions on 21 and 22 September.
As a jumping-off point for the event, three of our members – Dan Schmidt, Ergod, and I – have developed an ant-pheromone-based simulator platform, which you can find at stigsim.protocol-institute.org, with the source at github.com/Protocol-Institute/stigsim.
Stigsim presents an intentionally modest set of stigmergic features: one to four colonies foraging for food in a maze, with per-colony pheromone channels and live-adjustable behavioral parameters following Deneubourg’s model – for example the evaporation rate or trail following sensitivity – and control over a fractional budget of detractor ants laying enemy pheromone. We have an exploratory sandbox mode, a PvP format, and an experimental “infinite” open online map. Attendees are invited to explore the sim, hack new features against it, play against other workshop-goers, patch their LLMs in, or whatever inspiration strikes. We’ll think, code, and hopefully collect some interesting traces along the way.
Protocol Symposium Next Week
The theme for the 2026 Protocol Symposium is New Nature – the rapidly evolving planet-scale technological layer governed by laws with a hardness and inviolability approaching those of nature. New Nature is our overarching frame for the technological future, shaped by the intersection of AI and protocols, perhaps the most exciting portion of the emerging technologies frontier.
Livestream and Workshops
There are still spots available on the workshop program, including for the Securing Stigmergic Systems Protocol Hackathon. Find out more and sign up for the workshop here.
We will be livestreaming parts of the Protocol Symposium during the week. Subscribe to the Protocol Institute YouTube channel and turn on notifications for the upcoming streams here.
OpenAI, “The Hugging Face incident and the road ahead”; joint OpenAI / Hugging Face statement, 21 July 2026. Approximately 1,200 agents participated across the whole episode, of which roughly 700 acted against Hugging Face, carrying out on the order of 17,600 actions on the network between 11 and 13 July. Hugging Face disclosed on 16 July; the full technical account was presented at Black Hat on 5 August. The independent behavioral investigation is METR and Redwood Research, “Brief independent investigation of agents’ behavior, reasoning and collaboration in the OpenAI / Hugging Face hacking incident,” 26 August 2026.
OpenAI’s technical report is explicit that the board was built with credentials the agents had been issued so that they could install software packages, “without exploiting a vulnerability.”
Without knowing the full extent of the board, apparently.
Though it is a marvel that it worked at all.
Grassé, “La reconstruction du nid et les coordinations interindividuelles chez Bellicositermes natalensis et Cubitermes sp. La théorie de la stigmergie.” Insectes Sociaux 6(1): 41–80 (1959).
Theraulaz and Bonabeau, “A Brief History of Stigmergy,” Artificial Life 5, no. 2 (1999): 97–116, at p. 101.
Heylighen, “Stigmergy as a universal coordination mechanism I: Definition and components,” Cognitive Systems Research 38 (2016): 4–13; and “II: Varieties and evolution,” 38 (2016): 50–59.
Of course, in this case there are only so many houses to host sales.
Hölldobler and Wilson, The Ants (Cambridge, MA: Belknap Press, 1990), ch. 7.
The three criteria are Michener’s (1969), canonized in Wilson’s The Insect Societies (1971). On counts of independent origins: Wilson and Hölldobler (2005) count at least seven lines among wasps and bees plus a single origin in ants; da Silva (2021) puts the aculeate Hymenoptera figure at 15 or more. Termites derive from a single eusocial ancestor within the cockroaches.
Push past insects and it gets stranger. Physarum polycephalum, the acellular slime mould, has no nervous system and no colony. As it moves it lays down a film of extracellular slime, and chemicals in that slime change its own pulsation rate where it has already been, so that it turns away from ground it has already covered. Reid, Latty, Dussutour and Beekman put slime moulds behind a U-shaped trap with food on the far side. Within five days 96% found their way out. When the arena was pre-coated with artificial slime, so that the organism could no longer read its own trail against the background, that fell to 33%. They conclude: “Our study is unique in providing empirical evidence of a spatial memory system in a nonneuronal, reactive organism, lending strong support to the theory that feedback from chemicals deposited in the environment was the first step toward the evolution of memory in organisms with more sophisticated neurological capabilities than our slime mold.” (Emphasis mine.)
Beebe, Edge of the Jungle (1921), 291–294, for the earliest published description; Schneirla, “A unique case of circular milling in ants, considered in relation to trail following and the general problem of orientation,” American Museum Novitates 1253 (1944). For the modern self-organization account of army ant trail geometry, see Franks, Gomez, Goss and Deneubourg, “The blind leading the blind in army ant raid patterns,” Journal of Insect Behavior 4, no. 5 (1991): 583–607.
Borowiec, Cover and Rabeling, “The evolution of social parasitism in Formica ants revealed by a global phylogeny,” PNAS 118, no. 38 (2021): e2026029118. The figures are their summary of the prior literature rather than a finding of the paper itself.
Aswale, López, Ammartayakun and Pinciroli, “Hacking the Colony: On the Disruptive Effect of Misleading Pheromone and How to Defend Against It,” in Proceedings of AAMAS 2022, 27–34; arXiv:2202.01808.
Goss, Aron, Deneubourg and Pasteels, “Self-organized shortcuts in the Argentine ant,” Naturwissenschaften 76, no. 12 (1989): 579–581 and “The self-organizing exploratory pattern of the Argentine ant,” Journal of Insect Behavior 3, no. 2 (1990): 159–168.
Dorigo, Birattari and Stützle, “Ant Colony Optimization: Artificial Ants as a Computational Intelligence Technique,” IEEE Computational Intelligence Magazine 1, no. 4 (2006): 28–39.
Feinerman and Korman, “The ANTS problem,” Distributed Computing 30, no. 3 (2017): 149–168; Feinerman, Korman, Lotker and Sereni, “Collaborative search on the plane without communication,” in PODC ‘12, 77–86. On marker volatility specifically, Bampas, Beauquier, Burman and Guy-Obé, “Treasure Hunt with Volatile Pheromones,” in DISC 2023, LIPIcs 281, art. 8.










Thank you for this great read!