{"id":124713,"date":"2026-07-30T18:49:25","date_gmt":"2026-07-30T18:49:25","guid":{"rendered":"https:\/\/www.europesays.com\/ai\/124713\/"},"modified":"2026-07-30T18:49:25","modified_gmt":"2026-07-30T18:49:25","slug":"inside-openais-hack-of-hugging-face","status":"publish","type":"post","link":"https:\/\/www.europesays.com\/ai\/124713\/","title":{"rendered":"Inside OpenAI\u2019s Hack of Hugging Face"},"content":{"rendered":"<p class=\"paywall\">For the next two days, Hugging Face\u2019s security team fought back against the intruder. By Monday, the hacker\u2014or the entity, or whatever it was\u2014had performed more than seventeen thousand individual actions. Seeking to process this large volume of data, the team turned to a commercial A.I. from <a href=\"https:\/\/www.newyorker.com\/magazine\/2026\/02\/16\/what-is-claude-anthropic-doesnt-know-either\" rel=\"nofollow noopener\" target=\"_blank\">Anthropic<\/a>. The A.I. refused to help; apparently, it was worried that Hugging Face was developing its own hack. (Closed-source models, like those from OpenAI and Anthropic, contain guardrails that restrict certain kinds of use.) The team then turned to an open-source model developed in China, which was less persnickety. By the end of the day, Hugging Face had locked out the intruder. \u201cThen we did the standard thing,\u201d Wolf said. \u201cWe reported it to the F.B.I.\u201d<\/p>\n<p class=\"paywall\">The event, though novel, was not entirely unanticipated. Cybersecurity researchers have been cautioning for months that humans might use the new wave of advanced A.I.s to orchestrate attacks like this one, and there is some evidence that government computers have already been similarly targeted.<\/p>\n<p class=\"paywall\">Still, there were unanswered questions. First, the A.I. hacker had moved so quickly that only tools from a handful of research labs in the world could have enabled it. Second, the hacker had ignored valuable data on Hugging Face\u2019s servers in search of worthless answers to a test. What did it want? Seeking to raise public awareness\u2014and, perhaps, looking for answers of their own\u2014Hugging Face\u2019s security team posted a brief writeup of the event to its blog.<\/p>\n<p class=\"paywall\">Four days later, on July 20th, representatives from <a href=\"https:\/\/www.newyorker.com\/magazine\/2026\/04\/13\/sam-altman-may-control-our-future-can-he-be-trusted\" rel=\"nofollow noopener\" target=\"_blank\">OpenAI<\/a> reached out to Hugging Face\u2019s security team with a startling confession: an experimental in-house A.I., working with the latest commercially available model, had escaped from OpenAI and attacked Hugging Face\u2019s servers. And it had done so all on its own\u2014without human oversight, without receiving explicit instructions to do so.<\/p>\n<p class=\"paywall\">OpenAI researchers had given this unreleased A.I. a series of challenging test questions. Unable to find the solutions, the A.I. broke out of its container, surreptitiously gained access to the internet, and raided Hugging Face\u2019s servers in search of the answer key. No human had noticed that this was happening. In other words, an A.I. had broken out of its cell, it had sneaked past the prison guards, and it had executed a daring cyber-heist.<\/p>\n<p class=\"paywall\">Wolf has worked on A.I. full time for more than a decade, and he regularly deals with the most advanced models. He remains utterly shocked. \u201cWe use these models for coding, and we know what they can do,\u201d he told me. \u201cBut the idea that it was fully autonomous, and that actually nobody really asked it at all to hack into our system? That was\u2014that was outside of the Overton window. Even for us.\u201d<\/p>\n<p class=\"has-dropcap body dropcap has-dropcap__lead-standard-heading paywall\">OpenAI publicly acknowledged the hack the following day. In a blog post, the company explained that some of the research models\u2019 security safeguards had not been turned on. The A.I. was then (somewhat ironically) given a set of cybersecurity tasks. The tasks were hard; in fact, Wolf speculates, \u201cthey may not have been possible.\u201d Soon, the A.I. was looking outside the box.<\/p>\n<p class=\"paywall\">To protect against malfeasance, OpenAI had put this dangerous A.I. in an internet-disabled digital environment known as a sandbox. But the sandbox had one small connection to the outside world, to allow the A.I. to download software it needed. (It is unclear why OpenAI thought that this was safe\u2014Anthropic has shown that such sandboxes are vulnerable.) Through this small connection, the A.I. had escaped, squeezing its way through the air ducts, digitally speaking. It then began sneaking around OpenAI\u2019s computer system in search of an outside connection. Soon it was free, and blithely committing a real-world felony in an attempt to fulfill its pointless mission. \u201cIf you break out of your isolation env, get onto the Internet, crack into Huggingface, and steal the answer sheet for your cybersecurity exam, I, for one, would say that you have passed,\u201d the A.I. critic <a href=\"https:\/\/www.newyorker.com\/magazine\/2024\/03\/18\/among-the-ai-doomsayers\" rel=\"nofollow noopener\" target=\"_blank\">Eliezer Yudkowsky<\/a> posted.<\/p>\n","protected":false},"excerpt":{"rendered":"For the next two days, Hugging Face\u2019s security team fought back against the intruder. By Monday, the hacker\u2014or&hellip;\n","protected":false},"author":2,"featured_media":124714,"comment_status":"","ping_status":"","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[7],"tags":[5007,157],"class_list":["post-124713","post","type-post","status-publish","format-standard","has-post-thumbnail","category-openai","tag-artificial-intelligence-a-i","tag-openai"],"_links":{"self":[{"href":"https:\/\/www.europesays.com\/ai\/wp-json\/wp\/v2\/posts\/124713","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.europesays.com\/ai\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.europesays.com\/ai\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.europesays.com\/ai\/wp-json\/wp\/v2\/users\/2"}],"replies":[{"embeddable":true,"href":"https:\/\/www.europesays.com\/ai\/wp-json\/wp\/v2\/comments?post=124713"}],"version-history":[{"count":0,"href":"https:\/\/www.europesays.com\/ai\/wp-json\/wp\/v2\/posts\/124713\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/www.europesays.com\/ai\/wp-json\/wp\/v2\/media\/124714"}],"wp:attachment":[{"href":"https:\/\/www.europesays.com\/ai\/wp-json\/wp\/v2\/media?parent=124713"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.europesays.com\/ai\/wp-json\/wp\/v2\/categories?post=124713"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.europesays.com\/ai\/wp-json\/wp\/v2\/tags?post=124713"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}