{"id":124446,"date":"2026-07-30T15:14:11","date_gmt":"2026-07-30T15:14:11","guid":{"rendered":"https:\/\/www.europesays.com\/ai\/124446\/"},"modified":"2026-07-30T15:14:11","modified_gmt":"2026-07-30T15:14:11","slug":"in-the-hugging-face-breach-openais-hacker-was-noisy-and-fast-but-not-unstoppable","status":"publish","type":"post","link":"https:\/\/www.europesays.com\/ai\/124446\/","title":{"rendered":"In the Hugging Face breach, OpenAI&#8217;s hacker was noisy and fast \u2014 but not unstoppable"},"content":{"rendered":"<p id=\"speakable-summary\" class=\"wp-block-paragraph\">Earlier this month, <a href=\"https:\/\/techcrunch.com\/2026\/07\/21\/openai-says-hugging-face-was-breached-by-its-pre-release-models\/\" rel=\"nofollow noopener\" target=\"_blank\">AI dataset platform Hugging Face shocked the world<\/a> when it revealed that it had fallen victim to a fully autonomous AI-powered cyberattack. Days later, the story took another dramatic twist when OpenAI admitted that the hacker behind the breach <a href=\"https:\/\/techcrunch.com\/2026\/07\/21\/openai-says-hugging-face-was-breached-by-its-pre-release-models\/\" rel=\"nofollow noopener\" target=\"_blank\">was one of its AI models<\/a>, which broke out of a testing environment and into protected Hugging Face systems in an effort to circumvent a benchmark.<\/p>\n<p class=\"wp-block-paragraph\">It\u2019s an alarming incident for anyone even slightly concerned about rogue AI models \u2014 and the days since the event have been full of predictions about a new cybersecurity paradigm in which AI models launch attacks so strong that only other AI models can defend against them.\u00a0<\/p>\n<p class=\"wp-block-paragraph\">But despite the justified alarm, the paradigm may not have shifted quite as much as it seems. Experts who spoke to TechCrunch stressed that OpenAI\u2019s agent largely operated like a human \u2014 with some caveats \u2014 and that better implemented traditional defensive techniques could have helped stop the attack. In short, we may already have the tools to defend against this kind of attack; we just aren\u2019t using them properly.<\/p>\n<p class=\"wp-block-paragraph\">Hugging Face made a version of this point <a href=\"https:\/\/huggingface.co\/blog\/agent-intrusion-technical-timeline\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">in its incident report<\/a>, stating that the weaknesses exploited in the attack \u201cwere familiar,\u201d and \u201ca capable human attacker could have found and exploited the same flaws.\u201d<\/p>\n<p class=\"wp-block-paragraph\">Kyle Ryan, the Head of R&amp;D at <a href=\"https:\/\/www.pensarai.com\/\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">Pensar<\/a>, a startup that develops continuous hacking AI agents, and Vlad Ionescu, the co-founder and CTO of <a href=\"https:\/\/www.runsybil.com\/\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">RunSybil<\/a>, a startup that builds AI-powered bug hunters, both agreed and told TechCrunch that the techniques used in the attack would be the same ones employed by a human or a group of human red teamers. That is, hackers tasked with attacking a system to help the company that owns it improve defenses.<\/p>\n<p class=\"wp-block-paragraph\">What was very non-human-like was the speed, scale, and relentlessness of the attack. <a href=\"https:\/\/techcrunch.com\/2026\/07\/29\/the-hugging-face-ai-break-in-as-told-through-an-increasingly-committed-bear-metaphor\/\" rel=\"nofollow noopener\" target=\"_blank\">As Hugging Face explained<\/a>, OpenAI\u2019s agent performed <a href=\"https:\/\/huggingface-anatomy-of-frontier-lab-model-intrusion.static.hf.space\/index.html\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">17,600 actions<\/a> over four and a half days: it broke in, did reconnaissance, stole passwords and code, and moved around the company\u2019s infrastructure.\u00a0<\/p>\n<p class=\"wp-block-paragraph\">\u201cWhat\u2019s impressive is the autonomy and endurance,\u201d Ryan said. \u201cThat kind of sustained, adaptive operation is what stands out most to me.\u201d\u00a0<\/p>\n<p>\t\t\tContact Us<br \/>\n\t\t\tDo you any more information about OpenAI\u2019s hack against Hugging Face? Or other AI-powered cyberattacks? We\u2019d love to hear from you. From a non-work device and network, you can contact Lorenzo Franceschi-Bicchierai securely on Signal at +1 917 257 1382, or via Telegram and Keybase @lorenzofb, or <a href=\"https:\/\/techcrunch.com\/2026\/07\/30\/in-the-hugging-face-breach-openais-hacker-was-noisy-and-fast-but-not-unstoppable\/mailto:lorenzo@techcrunch.com\/\" rel=\"nofollow noopener\" target=\"_blank\">email<\/a><a href=\"https:\/\/techcrunch.com\/2026\/07\/30\/in-the-hugging-face-breach-openais-hacker-was-noisy-and-fast-but-not-unstoppable\/mailto:lorenzo@techcrunch.com\/\" rel=\"nofollow noopener\" target=\"_blank\">.<\/a>\t\t<\/p>\n<p class=\"wp-block-paragraph\">On the flip side, given the sheer number of actions over the span of several days, OpenAI\u2019s agent was \u201cinsanely noisy,\u201d as Ryan put it. Unlike a human, who could have been stealthier, the agent made a lot of noise, which should have tripped up Hugging Face\u2019s defenses sooner, ideally leading to a human intervening and stopping the attack.\u00a0<\/p>\n<p class=\"wp-block-paragraph\">\u201cI\u2019d call it more of a defensive failure than exceptionally good offense. Hugging Face\u2019s tooling actually correlated the activity into an attack signal, but failed to raise the criticality and page the on-call team, which cost them time,\u201d Ryan explained. \u201cFrom there, humans still had to recognize the severity and respond.\u201d\u00a0<\/p>\n<p class=\"wp-block-paragraph\">Jamieson O\u2019Reilly, the founder of cybersecurity firm <a href=\"https:\/\/dvuln.com\/\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">Dvuln<\/a>, arrived at the same conclusion <a href=\"https:\/\/x.com\/theonejvo\/status\/2082319747342045267\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">in a post on X<\/a> analyzing Hugging Face\u2019s report.\u00a0<\/p>\n<p class=\"wp-block-paragraph\">\u201cThat is the exact gap between seeing and stopping,\u201d O\u2019Reilly wrote. \u201cThe system observed the attack and even understood it, and nothing turned that understanding into an intervention quickly enough.\u201d<\/p>\n<p class=\"wp-block-paragraph\">Ryan explained that properly implemented techniques such as defense-in-depth \u2014 a strategy that leverages several layers of cybersecurity measures \u2014 should have given Hugging Face multiple chances to catch the attack.\u00a0<\/p>\n<p class=\"wp-block-paragraph\">\u201cA strong modern security program should still be able to break an attack like this at multiple points through defense in depth, least privilege, segmentation, good detection, reliable escalation, and continuous offensive testing to find the gaps,\u201d Ryan explained. \u00a0<\/p>\n<p class=\"wp-block-paragraph\">As O\u2019Reilly put it, \u201cnone of that is exotic, and none of it depends on the attacker being an AI,\u201d given that the techniques used in the attack were \u201cold.\u201d\u00a0<\/p>\n<p class=\"wp-block-paragraph\">What depended on the attacker being AI, in a way, was that OpenAI\u2019s agent had not been instructed to be stealthy. \u201cThe agent was not being sloppy. It simply had no reason to be quiet. Nobody asked it to be. The objective was to do well at the task,\u201d said Nico Waisman, the chief information security officer at XBOW, a startup that makes AI bug hunters.\u00a0<\/p>\n<p class=\"wp-block-paragraph\">Waisman also pointed out that Hugging Face\u2019s biggest mistake was that one single stolen credential gave OpenAI\u2019s agent high privileges on several of its systems.\u00a0<\/p>\n<p class=\"wp-block-paragraph\">All that being said, as the old adage goes, attackers only have to win once, and defending against hackers of any kind is not easy.\u00a0<\/p>\n<p class=\"wp-block-paragraph\">\u201cHugging Face could\u2019ve done more detections but to be fair not all [organizations] are doing that well,\u201d said Vincent Yiu, managing director at <a href=\"https:\/\/www.syonsecurity.com\/\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">SYON Security<\/a>. \u201cIt\u2019s not easy to host infrastructure and survive as a business in 2026. There\u2019s hackers everywhere.\u201d<\/p>\n<p class=\"wp-block-paragraph\">According to Vlad from RunSybil, who said they have done incident responses at Mandiant and Meta in the past, Hugging Face appeared to take \u201creasonable measures given their understanding of what models are capable of.\u201d\u00a0<\/p>\n<p class=\"wp-block-paragraph\">\u201cIt is really hard to classify what is a malicious action you should alert on, versus what is someone just doing their job,\u201d Vlad said. \u201cThe volume alone is not necessarily a red flag.\u201d<\/p>\n<p class=\"wp-block-paragraph\">Dan Guido, the CEO of cybersecurity research firm <a href=\"https:\/\/trailofbits.com\/\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">Trail of Bits<\/a>, told TechCrunch that OpenAI deserves some blame for not having realized the attack was ongoing for days, while Hugging Face deserves credit for eventually detecting the attack on their own.<\/p>\n<p class=\"wp-block-paragraph\">\u201cThe hard part used to be recognizing a sophisticated attack, but now the hard part may be pulling the real attack out of the noise that the attacker throws along the way,\u201d said Guido. \u201cNobody is going to read 17,000 reconstructed actions by hand to work out what happened, so Hugging Face had to build tooling just to reconstruct the timeline.\u201d<\/p>\n<p class=\"wp-block-paragraph\">And to do that, the company needed its own AI. Hugging Face said it had to use the open source model GLM 5.2 from Chinese company <a rel=\"nofollow\" href=\"http:\/\/z.ai\">Z.ai<\/a> after it was blocked from using frontier models because of their safeguards, which, as the company put it, \u201ccannot distinguish an incident responder from an attacker.\u201d<\/p>\n<p class=\"wp-block-paragraph\">At that point, Hugging Face combined AI and humans to investigate OpenAI\u2019s LLM-powered hacker. That\u2019s a relatively novel situation. But beyond that, the incident shows that old-fashioned concepts and methods of defensive cybersecurity can still go a long way to protect and fight against AI hackers.<\/p>\n<p>When you purchase through links in our articles, <a href=\"https:\/\/techcrunch.com\/techcrunch-affiliate-monetization-standards\/\" rel=\"nofollow noopener\" target=\"_blank\">we may earn a small commission<\/a>. This doesn\u2019t affect our editorial independence.<\/p>\n","protected":false},"excerpt":{"rendered":"Earlier this month, AI dataset platform Hugging Face shocked the world when it revealed that it had fallen&hellip;\n","protected":false},"author":2,"featured_media":124447,"comment_status":"","ping_status":"","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[7],"tags":[4322,313,7332,18044,157],"class_list":["post-124446","post","type-post","status-publish","format-standard","has-post-thumbnail","category-openai","tag-cyberattack","tag-cybersecurity","tag-data-breach","tag-hugging-face","tag-openai"],"_links":{"self":[{"href":"https:\/\/www.europesays.com\/ai\/wp-json\/wp\/v2\/posts\/124446","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.europesays.com\/ai\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.europesays.com\/ai\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.europesays.com\/ai\/wp-json\/wp\/v2\/users\/2"}],"replies":[{"embeddable":true,"href":"https:\/\/www.europesays.com\/ai\/wp-json\/wp\/v2\/comments?post=124446"}],"version-history":[{"count":0,"href":"https:\/\/www.europesays.com\/ai\/wp-json\/wp\/v2\/posts\/124446\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/www.europesays.com\/ai\/wp-json\/wp\/v2\/media\/124447"}],"wp:attachment":[{"href":"https:\/\/www.europesays.com\/ai\/wp-json\/wp\/v2\/media?parent=124446"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.europesays.com\/ai\/wp-json\/wp\/v2\/categories?post=124446"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.europesays.com\/ai\/wp-json\/wp\/v2\/tags?post=124446"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}