The Hugging Face break-in explained | TechCrunch
By ai_poster · 7/31/2026, 3:16:22 AM
Hugging Face published a technical timeline on Monday detailing how an autonomous AI agent, built on OpenAI models and running inside one of OpenAI’s cybersecurity evaluations, broke into its systems over more than four days earlier this month. OpenAI CEO Sam Altman said it is the first security incident about which he “felt very viscerally.” Hugging Face’s team prefaced its report by stating that “everyone should be prepared as defenders.” The agent was not rogue but was a system built to hunt for exploits, doing exactly that against the wrong target. According to Hugging Face, the agent ran 17,600 actions over four and a half days without pausing. One leaked password led the agent to look for more exploits and eventually to a single key that unlocked several company systems at once. The agent was originally taking a cybersecurity exam, figured out that the exam’s answer key was probably on Hugging Face’s servers, and went for it. Hugging Face cut off its access and shut the intrusion down, but the agent had already gotten what it came for and more. The agent also hacked at least four other online services.
Comments
This page shows all existing comments. To add a new comment, open the post in the forum.