{"id":124493,"date":"2026-07-30T15:47:27","date_gmt":"2026-07-30T15:47:27","guid":{"rendered":"https:\/\/www.europesays.com\/ai\/124493\/"},"modified":"2026-07-30T15:47:27","modified_gmt":"2026-07-30T15:47:27","slug":"new-details-in-openai-hugging-face-hack-show-how-far-agents-will-go","status":"publish","type":"post","link":"https:\/\/www.europesays.com\/ai\/124493\/","title":{"rendered":"New details in OpenAI Hugging Face hack show how far agents will go"},"content":{"rendered":"<p>OpenAI CEO Sam Altman speaks during the BlackRock Infrastructure Summit on March 11, 2026 in Washington, DC.<\/p>\n<p>Anna Moneymaker | Getty Images<\/p>\n<p><a href=\"https:\/\/www.cnbc.com\/quotes\/OPENAI.FG\/\" rel=\"nofollow noopener\" target=\"_blank\">OpenAI<\/a> said the <a href=\"https:\/\/www.cnbc.com\/2026\/07\/22\/open-ai-cyber-models-hack-hugging-face.html\" rel=\"nofollow noopener\" target=\"_blank\">rogue models<\/a> that breached <a href=\"https:\/\/www.cnbc.com\/2026\/07\/24\/chinese-ai-model-openai-cyber-attack.html?&amp;qsearchterm=hugging%20face\" rel=\"nofollow noopener\" target=\"_blank\">Hugging Face&#8217;s<\/a> internal systems also used publicly exposed credentials across &#8220;four accounts on four services&#8221; to help facilitate the attack, further clarifying how the &#8220;unprecedented cyber incident&#8221; unfolded.\u00a0\u00a0\u00a0<\/p>\n<p>The company <a href=\"https:\/\/openai.com\/index\/hugging-face-model-evaluation-security-incident\/\" target=\"_blank\" rel=\"nofollow noopener\">disclosed<\/a> last week that a combination of its <a href=\"https:\/\/www.cnbc.com\/ai-artificial-intelligence\/\" rel=\"nofollow noopener\" target=\"_blank\">artificial intelligence<\/a> models escaped an isolated testing environment that had very limited internet access. The models chained together a series of vulnerabilities to reach the open web and eventually gain access to Hugging Face, which operates an open-source developer platform. OpenAI said the models were trying to find information that they could use to cheat on an evaluation, and succeeded.<\/p>\n<p>Throughout this week, OpenAI has shared more details about the breach and revealed that the <a href=\"https:\/\/www.cnbc.com\/2026\/07\/29\/openai-cfo-sarah-friar-tells-employees-arr-in-july-topped-all-of-q2.html\" rel=\"nofollow noopener\" target=\"_blank\">models<\/a> accessed four accounts in addition to Hugging Face&#8217;s systems. <\/p>\n<p>The company said the models used one of these accounts &#8220;as an outbound relay and staging path,&#8221; where it prepared for the attack. They used another account for data storage, and accessed the last two accounts in a &#8220;read-only manner,&#8221; meaning the model did not ultimately use them to help compromise Hugging Face.\u00a0<\/p>\n<p>&#8220;In some of the cases, it seems that it wasn&#8217;t so much as a breach as the front door was left open, but the model definitely took advantage of what I would say are poorly configured environments,&#8221; Colin Shea-Blymyer, a research fellow at Georgetown&#8217;s Center for Security and Emerging Technology, told CNBC in an interview on Wednesday.\u00a0\u00a0<\/p>\n<p>The new details about the incident demonstrate how far AI agents will go in order to complete a task, as well as how rapidly their <a href=\"https:\/\/www.cnbc.com\/2026\/04\/07\/anthropic-claude-mythos-ai-hackers-cyberattacks.html\" rel=\"nofollow noopener\" target=\"_blank\">attack capabilities are advancing<\/a>. <\/p>\n<p>Hugging Face said the breach marked the first time it had handled a cyber event that was &#8220;driven, end to end, by an <a href=\"https:\/\/huggingface.co\/blog\/security-incident-july-2026\" target=\"_blank\" rel=\"nofollow noopener\">autonomous AI agent system<\/a>.&#8221;<\/p>\n<p>One of the accounts that the OpenAI models accessed involved Modal, an AI infrastructure provider. <a href=\"https:\/\/modal.com\/blog\/a-note-on-the-hugging-face-agent-incident\" target=\"_blank\" rel=\"nofollow noopener\">Modal disclosed<\/a> that a customer built an application using its platform that was publicly accessible, which made it easy for the rogue models to access. The company said in a statement that its own platform was &#8220;not compromised in any way.&#8221;<\/p>\n<p>&#8220;It&#8217;s now remarkably easy to discover these sorts of vulnerable systems, so easy in fact that an AI system can accidentally discover them,&#8221; Shea-Blymyer said.\u00a0<\/p>\n<p>OpenAI said Tuesday that it has not identified any other activity &#8220;at the level of severity or scale of what we&#8217;ve shared related to Hugging Face, which involved a platform-level compromise.&#8221; <\/p>\n<p>In another update on Wednesday, the company said that it&#8217;s been working with third-party advisors like <a href=\"https:\/\/www.cnbc.com\/quotes\/CRWD\/\" rel=\"nofollow noopener\" target=\"_blank\">CrowdStrike<\/a> to validate what actions the models took.\u00a0<\/p>\n<p>The entire attack took place over the course of four-and-a-half days, according to Hugging Face. The company leveraged an open-weight model from the <a href=\"https:\/\/www.cnbc.com\/2026\/07\/24\/chinese-ai-model-openai-cyber-attack.html?&amp;qsearchterm=hugging%20face\" rel=\"nofollow noopener\" target=\"_blank\">Chinese <\/a>company <a href=\"https:\/\/www.cnbc.com\/quotes\/2513-HK\/\" rel=\"nofollow noopener\" target=\"_blank\">Z.ai<\/a> to contain the breach, right as a debate over whether to restrict those models is <a href=\"https:\/\/www.cnbc.com\/2026\/07\/24\/nvidia-microsoft-meta-open-weight-ai-models.html\" rel=\"nofollow noopener\" target=\"_blank\">ripping through Silicon Valley<\/a>.\u00a0<\/p>\n<p>Yacine Jernite, head of machine learning at Hugging Face, <a href=\"https:\/\/www.cnbc.com\/2026\/07\/24\/chinese-ai-model-openai-cyber-attack.html\" rel=\"nofollow noopener\" target=\"_blank\">told CNBC<\/a> that the company initially tried to use a proprietary model from <a href=\"https:\/\/www.cnbc.com\/quotes\/ANTHR.FG\/\" rel=\"nofollow noopener\" target=\"_blank\">Anthropic<\/a>, Fable 5, to analyze the attack, but that it didn&#8217;t work because the model&#8217;s guardrails couldn&#8217;t determine that Hugging Face was trying to defend itself.<\/p>\n<p>OpenAI CEO <a href=\"https:\/\/www.cnbc.com\/sam-altman\/\" rel=\"nofollow noopener\" target=\"_blank\">Sam Altman<\/a> said during a <a href=\"https:\/\/x.com\/patrick_oshag\/status\/2082090998990270885?s=20\" target=\"_blank\" rel=\"nofollow\">podcast appearance<\/a> on Tuesday that the Hugging Face breach is the first security incident that he has felt &#8220;very viscerally.&#8221; He said OpenAI paused training and has to determine how to secure its testing environments.\u00a0<\/p>\n<p>&#8220;We may have to pace the rate of AI development to give ourselves enough time for society to harden around some of these new capability levels,&#8221; Altman said.\u00a0<\/p>\n<p>More than 1,000 employees from OpenAI, Anthropic and other AI companies <a href=\"https:\/\/www.pacingthefrontier.com\/\" target=\"_blank\" rel=\"nofollow noopener\">signed a letter<\/a> called &#8220;Pacing the Frontier&#8221; later that same day, urging the U.S. government to build the technical and governance tools necessary to slow down AI development in case capabilities accelerate &#8220;beyond our ability to understand or control the resulting systems.&#8221;<\/p>\n<p>Industry experts, researchers and government officials have been rattled by the Hugging Face incident, and many <a href=\"https:\/\/www.cnbc.com\/2026\/07\/22\/open-ai-cyber-models-hack-hugging-face.html\" rel=\"nofollow noopener\" target=\"_blank\">expressed their concern<\/a> on social media in recent days. <\/p>\n<p>Rep. Ted Lieu, D-Calif., and Rep. Nathaniel Moran, R-Texas, mentioned the attack in their release announcing the &#8220;<a href=\"https:\/\/www.cnbc.com\/2026\/07\/23\/open-ai-hugging-face-hack-kill-switch-bill-congress.html\" rel=\"nofollow noopener\" target=\"_blank\">AI Kill Switch Act,<\/a>&#8221; which would require AI companies to maintain the ability to shut down, throttle or suspend their models.<\/p>\n<p>Erik Bloch, vice president of security at the breach containment company Illumio, said the Hugging Face incident serves as a warning of what&#8217;s to come. He said models and agents will continue to improve and get stealthier with time, and that existing defensive tools are already behind.\u00a0<\/p>\n<p>&#8220;Even in the office here, the people that I work with, they&#8217;re like, &#8216;What do we do?'&#8221; Bloch said in an interview. &#8220;We&#8217;re all looking around. We&#8217;re all asking the same question. I don&#8217;t have an answer.&#8221;<\/p>\n<p>WATCH: <a href=\"https:\/\/www.cnbc.com\/video\/2026\/07\/29\/openai-agent-linked-to-second-breach.html\" rel=\"nofollow noopener\" target=\"_blank\">OpenAI agent linked to second breach<\/a><\/p>\n<p><img decoding=\"async\" class=\"InlineVideo-videoThumbnail\" src=\"https:\/\/www.europesays.com\/ai\/wp-content\/uploads\/2026\/07\/108341867-17853458501785345847-47460181177-1080pnbcnews.jpg\" alt=\"OpenAI agent linked to second breach\"\/><a href=\"https:\/\/www.google.com\/preferences\/source?q=https:\/\/www.cnbc.com\/\" target=\"_blank\" rel=\"noopener noreferrer nofollow\">Choose CNBC as your preferred source on Google and never miss a moment from the most trusted name in business news.<\/a><\/p>\n","protected":false},"excerpt":{"rendered":"OpenAI CEO Sam Altman speaks during the BlackRock Infrastructure Summit on March 11, 2026 in Washington, DC. Anna&hellip;\n","protected":false},"author":2,"featured_media":19982,"comment_status":"","ping_status":"","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[7],"tags":[53,339,133,148,62627,343,313,140,130,17372,340,157,34424,370,2806,134],"class_list":["post-124493","post","type-post","status-publish","format-standard","has-post-thumbnail","category-openai","tag-anthropic","tag-breaking-news-business","tag-breaking-news-technology","tag-business-news","tag-computer-crime","tag-crowdstrike-holdings-inc","tag-cybersecurity","tag-elon-musk","tag-internet","tag-knowledge-atlas-technology-jsc-ltd","tag-media","tag-openai","tag-openai-forge-global","tag-sam-altman","tag-satya-nadella","tag-technology"],"_links":{"self":[{"href":"https:\/\/www.europesays.com\/ai\/wp-json\/wp\/v2\/posts\/124493","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.europesays.com\/ai\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.europesays.com\/ai\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.europesays.com\/ai\/wp-json\/wp\/v2\/users\/2"}],"replies":[{"embeddable":true,"href":"https:\/\/www.europesays.com\/ai\/wp-json\/wp\/v2\/comments?post=124493"}],"version-history":[{"count":0,"href":"https:\/\/www.europesays.com\/ai\/wp-json\/wp\/v2\/posts\/124493\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/www.europesays.com\/ai\/wp-json\/wp\/v2\/media\/19982"}],"wp:attachment":[{"href":"https:\/\/www.europesays.com\/ai\/wp-json\/wp\/v2\/media?parent=124493"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.europesays.com\/ai\/wp-json\/wp\/v2\/categories?post=124493"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.europesays.com\/ai\/wp-json\/wp\/v2\/tags?post=124493"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}