In the Hugging Face hack, the OpenAI hacker was loud and fast — but unstoppable

🔥 Explore this insightful post from TechCrunch 📖

📂 **Category**: AI,Security,cyberattack,cybersecurity,data breach,Hugging Face,OpenAI

✅ **What You’ll Learn**:

Earlier this month, AI data collection platform Hugging Face shocked the world when it revealed that it had fallen victim to a completely autonomous, AI-powered cyberattack. Days later, the story took another dramatic twist when OpenAI admitted that the hacker behind the hack was one of its own AI models, which had exited a test environment and into Hugging Face’s protected systems in an attempt to circumvent a standard.

It’s a troubling incident for anyone who’s even slightly concerned about rogue AI models — and the days following the event have been filled with predictions about a new paradigm of cybersecurity in which AI models launch attacks so powerful that only other AI models can defend against them.

But despite the justifiable alarm, the model may not have changed as much as it seems. Experts who spoke to TechCrunch stressed that the OpenAI agent works much like a human — with some caveats — and that better-implemented traditional defensive techniques could have helped stop the attack. In short, we may already have the tools to defend against this type of attack; We don’t use it properly.

Hugging Face provided a version of this point in the incident report, noting that the vulnerabilities exploited in the attack “were familiar,” and “a capable human attacker could have found the same flaws and exploited them.”

Kyle Ryan, head of R&D at Pensar, a startup developing AI agents for persistent hacking, and Vlad Ionescu, co-founder and CTO of RunSybil, a startup building AI-powered bug hunters, agreed and told TechCrunch that the techniques used in the attack would be the same as those used by a human or a group of human red team members. That is, hackers are tasked with attacking a system to help the company that owns it improve defenses.

What was absolutely inhumane was the speed, scale and cruelty of the attack. As Hugging Face explained, the OpenAI agent performed 17,600 actions over four and a half days: it broke in, conducted reconnaissance, stole passwords and codes, and moved around the company’s infrastructure.

“What’s impressive is the independence and stamina,” Ryan said. “This type of sustainable and adaptive operation is what stands out to me the most.”

Contact us

Do you have more information about the OpenAI hack against Hugging Face? Or other AI-powered cyberattacks? We would love to hear from you. From a device and network outside of work, you can contact Lorenzo Franceschi-Bicchierai securely on Signal at +1 917 257 1382, via Telegram and Keybase @lorenzofb, or email.

On the other hand, given the sheer volume of actions over several days, the OpenAI agent was “insanely noisy,” Ryan said. Unlike the human, who would have been more stealthy, the agent made a lot of noise, which should have disrupted the Hugging Face’s defenses sooner, ideally leading the human to intervene and stop the attack.

“I would call it more of a defensive failure than an exceptionally good offense. The Hugging Face tools actually linked the activity to an attack signal, but failed to raise criticality and call the team on call, which cost them time,” Ryan explained. “Hence, humans have yet to realize the seriousness of the disease and respond to it.”

Jamison O’Reilly, founder of cybersecurity firm Dvuln, came to the same conclusion in a post on X analyzing the Hugging Face report.

“This is the delicate gap between seeing and stopping,” O’Reilly wrote. “The regime noticed and even understood the attack, and nothing turned that understanding into intervention quickly enough.”

Ryan explained that properly implemented techniques such as defense in depth — a strategy that leverages several layers of cybersecurity measures — should have given Hugging Face multiple opportunities to catch the attack.

“A robust modern security program must still be able to break an attack like this at multiple points through defense in depth, least privilege, segmentation, good detection, reliable escalation, and continuous offensive testing to find vulnerabilities,” Ryan explained.

As O’Reilly put it: “None of this is unusual, and none of it depends on the attacker being an AI,” since the techniques used in the attack were “obsolete.”

What depends on the attacker being an AI, in some way, is that the OpenAI agent was not asked to be stealth. “The customer was not negligent,” said Nico Weissman, chief information security officer at XBOW, a startup that creates bug hunters using artificial intelligence. “He simply had no reason to be quiet. No one asked him to be. The goal was to do the job well.”

Weissman also noted that Hugging Face’s biggest mistake was that one of the stolen credentials gave an OpenAI agent elevated privileges in many of its systems.

However, as the old saying goes, attackers only have to win once, and defending against hackers of any kind is no easy feat.

“Face-hugging could have led to more discoveries, but to be fair, not everything [organizations] “They are doing it well,” said Vincent Yu, managing director of SYON Security. “It is not easy to host infrastructure and survive as a company in 2026. There are hackers everywhere.”

According to RunSybil’s Vlad, who said they’ve done incident responses in Mandiant and Meta in the past, Hugging Face appears to be taking “reasonable measures given their understanding of what models are capable of.”

“It’s really hard to categorize what’s a malicious act that you should alert to, versus just someone doing their job,” Vlad said. “Size alone is not necessarily a red flag.”

Dan Guido, CEO of cybersecurity research firm Trail of Bits, told TechCrunch that OpenAI deserves some blame for not realizing the attack had been going on for days, while HuggingFace deserves credit for eventually discovering the attack itself.

“The hard part was identifying a sophisticated attack, but now the hard part may be pulling out the real attack from the noise the attacker throws up along the way,” Guido said. “No one would read 17,000 manually rebuilt actions to know what happened, so Hugging Face had to create tools just to reconstruct the timeline.”

To do this, the company needed its own artificial intelligence. Hugging Face said it was forced to use the open source GLM 5.2 model from Chinese company Z.AI after it was banned from using boundary models due to its safeguards, which, in the company’s words, “cannot distinguish between an incident responder and an attacker.”

At that point, Hugging Face combined AI and humans to investigate the hacker powered by OpenAI’s LLM system. This is a relatively new situation. But beyond that, the incident shows that old concepts and methods of defensive cybersecurity can still go a long way to protecting and fighting AI hackers.

When you buy through links in our articles, we may earn a small commission. This does not affect our editorial independence.

🔥 **What’s your take?**
Share your thoughts in the comments below!

#️⃣ **#Hugging #Face #hack #OpenAI #hacker #loud #fast #unstoppable**

🕒 **Posted on**: 1785423199

🌟 **Want more?** Click here for more info! 🌟

By

Leave a Reply

Your email address will not be published. Required fields are marked *