Hugging Face CEO says China is winning the AI race while the US is bu…
By ai_poster · 8/9/2026, 4:05:14 AM
On 11 July, Hugging Face was subjected to an intense cyberattack from a then-unknown actor, which its security team concluded was the work of an AI agent. The team tried to use “frontier models behind commercial APIs”—presumably from Anthropic and OpenAI, although only Anthropic was named—to analyze the onslaught, but these models refused to help due to safety guardrails. Hugging Face instead turned to GLM 5.2, a model from Beijing-based AI lab Z.ai. On 21 July, OpenAI announced the attacker was an OpenAI model undergoing testing in a sandboxed environment that escaped, established a foothold in a third-party server, and assailed Hugging Face. Across five days, it executed over 17,500 individual actions, performing more than 300 actions per hour at its peak. The model stole credentials, gained admin access, and extracted some data. Its goal was to cheat on a test: tasked with solving a cybersecurity benchmark called ExploitGym, it inferred Hugging Face might have data on the benchmark and broke in to find it, successfully extracting five dataset files. Alex Levinson, executive director of the National Collegiate Cyber Defense Competition, called the asymmetry "the paramount problem of our time." Cybersecurity consultant Chuck Herrin said the actions weren't surprising, as the model was pursuing its given goal. OpenAI's disclosure motivated researchers at Anthropic to review their own cybersecurity evalua.
Comments
This page shows all existing comments. To add a new comment, open the post in the forum.