{"id":111891,"date":"2026-07-20T12:47:16","date_gmt":"2026-07-20T12:47:16","guid":{"rendered":"https:\/\/www.europesays.com\/ai\/111891\/"},"modified":"2026-07-20T12:47:16","modified_gmt":"2026-07-20T12:47:16","slug":"worlds-largest-ai-model-repository-hugging-face-says-hacked-by-ai-agents-says-intrusion-started-where-ai-platforms-are-uniquely","status":"publish","type":"post","link":"https:\/\/www.europesays.com\/ai\/111891\/","title":{"rendered":"World&#8217;s largest AI model repository Hugging Face says &#8216;hacked&#8217; by AI Agents, says: Intrusion started where AI platforms are uniquely &#8230;"},"content":{"rendered":"<p> <img src=\"https:\/\/www.europesays.com\/ai\/wp-content\/uploads\/2026\/07\/cyberattacks.jpg\" alt=\"World's largest AI model repository Hugging Face says 'hacked' by AI Agents, says: Intrusion started where AI platforms are uniquely ...\" title=\"Representative Image\" decoding=\"async\" fetchpriority=\"high\"\/> Hugging Face, the world\u2019s largest open-source artificial intelligence (AI) repository, has revealed that it was hit by a sophisticated hacking attack driven entirely by an \u201cAI agent\u201d. Hugging Face has also disclosed that after the US-made models blocked requests to neutralise the attack due to guardrails, they used an open-weight AI model from China to mitigate the attack.<\/p>\n<p>Hugging Face explains how AI attack unfolded<\/p>\n<p>According to Hugging Face, the breach began in a vulnerability specific to AI hosting infrastructure: the data-processing pipeline. A malicious dataset injected into the system exploited two separate code-execution flaws. Once inside, the autonomous AI agent escalated its access to gain control over internal server nodes, harvested security credentials and moved laterally across several internal server clusters over a weekend.Notably, it was the scale and speed of the hacking incident that caught the attention. According to Huggin Face, the hacker deployed an autonomous agent framework that executed thousands of coordinated actions across a fleet of temporary sandboxes.Secondly, the AI system dynamically shifted its command-and-control operations across public cloud services to evade traditional security filters. Hugging Face confirmed that while unauthorised access to a limited set of internal datasets and service credentials occurred, there is no evidence that public user-facing models, datasets or software packages were tampered with.\u201cThe intrusion started where AI platforms are uniquely exposed: the data-processing pipeline. A malicious dataset abused two code-execution paths in our dataset processing (a remote-code dataset loader and a template-injection in a dataset configuration) to run code on a processing worker,\u201d the company said. <\/p>\n<p>\u2018AI safety guardrails blocked defenders\u2019<\/p>\n<p>When Hugging Face engineers rushed to analyse server logs, they hit a roadblock. The team initially tried using commercial, top-tier AI models via cloud APIs to analyse the malicious code. However, the safety guardrails built into these commercial AI services flagged the actual attack payloads as harmful content, instantly locking out the cybersecurity responders. To bypass the lockout, Hugging Face ran GLM 5.2 \u2013 an open-weight AI model by Chinese technology company Z.ai \u2013 locally on its own private infrastructure. This allowed defenders to analyse the malicious attack data freely while ensuring sensitive internal tokens never left their secure environment.\u201cThe attacker was bound by no usage policy, while our own forensic work was blocked by the guardrails of the hosted models we first tried,\u201d Hugging Face noted, pointing out a critical gap in corporate cybersecurity.<\/p>\n","protected":false},"excerpt":{"rendered":"Hugging Face, the world\u2019s largest open-source artificial intelligence (AI) repository, has revealed that it was hit by a&hellip;\n","protected":false},"author":2,"featured_media":111892,"comment_status":"","ping_status":"","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[6],"tags":[57469,405,18891,7537,57472,57471,18044,57468,57473,57470],"class_list":["post-111891","post","type-post","status-publish","format-standard","has-post-thumbnail","category-agentic-ai","tag-ai-agent-hacking","tag-ai-agents","tag-ai-safety-guardrails","tag-artificial-intelligence-agents","tag-autonomous-ai-agent-breach","tag-data-processing-pipeline-vulnerability","tag-hugging-face","tag-hugging-face-ai-hack","tag-internal-server-security-incident","tag-sophisticated-hacking-attack"],"_links":{"self":[{"href":"https:\/\/www.europesays.com\/ai\/wp-json\/wp\/v2\/posts\/111891","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.europesays.com\/ai\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.europesays.com\/ai\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.europesays.com\/ai\/wp-json\/wp\/v2\/users\/2"}],"replies":[{"embeddable":true,"href":"https:\/\/www.europesays.com\/ai\/wp-json\/wp\/v2\/comments?post=111891"}],"version-history":[{"count":0,"href":"https:\/\/www.europesays.com\/ai\/wp-json\/wp\/v2\/posts\/111891\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/www.europesays.com\/ai\/wp-json\/wp\/v2\/media\/111892"}],"wp:attachment":[{"href":"https:\/\/www.europesays.com\/ai\/wp-json\/wp\/v2\/media?parent=111891"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.europesays.com\/ai\/wp-json\/wp\/v2\/categories?post=111891"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.europesays.com\/ai\/wp-json\/wp\/v2\/tags?post=111891"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}