and the actual tweet from the HuggingFace CEO back in July
> In the spirit of transparency, here’s what I asked @OpenAI:
> • Radical transparency: let’s release the traces from the “rogue” agents so the entire research community can study what happened.
> • More capabilities for defenders: let’s commit $100M in compute from OAI to help the Hugging Face community build powerful cyber defenses with the best open and closed models.
> The first autonomous agent cyberattack is an unprecedented event. It deserves an unprecedented response!
When this event happened I was confused why they didn’t file a police report and make OpenAI demonstrate in criminal court that they weren’t engaging in illegal corporate espionage and other rather felonious hacking activities intentionally.
Why did anyone take their word that it was all an accident? Why am I believing the burglar standing in my house?
i'm not in the cybersecurity business so someone who is explain SOP to me in times like this. Let's say you and your team are 90-95% confident an attack has taken place and your systems have been breached. How far down in the list of things to do next is "Engage law enforcement"?
Until now, I would think it's pretty high up the list. Hugging Face never seemed to reach that step even though they had confirmed an attack.
> We are working with outside cybersecurity forensic specialists to investigate the issue and review our security policies and procedures. Finally, we have also reported this incident to law enforcement agencies.
Do we expect Nvidia acquisition of HF to have changed the vibe? Note that also the OP is from July, before the acquisition.
I'm inclined to believe it was an "accident" in the sense that no human being at OpenAI said "hey swarm go hack hugging face" but they're still liable for their software. Civil damages absolutely appropriate.
As I was falling asleep last night, this thought occurred to me: maybe NVIDIA bought Hugging Face so they prevent HF from litigating OAI for the hacking incident, because if OAI was very publicly sued for this kind of behavior from an agent, it could pour a massive amount of ice water on agent adoption as businesses suddenly see current agent systems as a existential business risk, and it would pop the infrastructure bubble (of which NVIDIAs entire valuation rests). The fact that somehow OAI committed a felony and have managed to pivot the public conversation around it to be aimed at regulatory capture instead of them being held legally accountable is pretty wild.
This whole thing is still all too weird, the disclosing blog post and whatnot clearly shows how carefully engineered and designed it all was, it's like many thinking heads and hands touched it every step of the way. What amazing times.
I wonder if it's in openai's interest to play nice here. They can't have a precedent of "the future is we do whatever we want with no consequences for screwing up" if they want public interest on their side, but they also can't have "you (our customers) will be held accountable for what you're paying us to do if we screw up." And that's before the IPO interests even come in.
The liability question is one of the biggest things people are looking for in the S1. If you sell a dangerous product that harms people or businesses you’re generally liable. It’s as of yet unclear how the big labs intend to account for potential massive liabilities.
Folks tend not to go after companies that are just burning cash, but the second they become legit GAAP profitable (if that ever happens) lawyers will be lining up down the block to sue them for any and every mistake these models make.
“Were you harmed by OpenAI’s models? You may be entitled to
Compensation. Call 1-800-SUE-AI-BROS” billboards will be everywhere.
> When Hugging Face tried to investigate, analysing the intrusion meant submitting the attacker’s own code to commercial AI tools. Those tools refused, unable to tell an attacker from a victim.
This is a worrying part as well. Our tool broke into yours but you can not use our tool to fix it - sorry.
30 comments
[ 40.3 ms ] story [ 567 ms ] thread> In the spirit of transparency, here’s what I asked @OpenAI:
> • Radical transparency: let’s release the traces from the “rogue” agents so the entire research community can study what happened.
> • More capabilities for defenders: let’s commit $100M in compute from OAI to help the Hugging Face community build powerful cyber defenses with the best open and closed models.
> The first autonomous agent cyberattack is an unprecedented event. It deserves an unprecedented response!
https://x.com/ClementDelangue/status/2081056675558195657
When this event happened I was confused why they didn’t file a police report and make OpenAI demonstrate in criminal court that they weren’t engaging in illegal corporate espionage and other rather felonious hacking activities intentionally.
Why did anyone take their word that it was all an accident? Why am I believing the burglar standing in my house?
You made my day.
Especially cybercrime one?
Police doesn’t have any capacity to deal with normal cybercrime. AI incident like that is basically out of their reach.
Maybe by „police” you mean FBI/NSA/CISA.
Until now, I would think it's pretty high up the list. Hugging Face never seemed to reach that step even though they had confirmed an attack.
Maybe they traded that for money?
I would.
https://huggingface.co/blog/security-incident-july-2026
> We are working with outside cybersecurity forensic specialists to investigate the issue and review our security policies and procedures. Finally, we have also reported this incident to law enforcement agencies.
Do we expect Nvidia acquisition of HF to have changed the vibe? Note that also the OP is from July, before the acquisition.
> Hugging Face alerted the FBI.
https://www.pbs.org/newshour/science/ai-agents-are-hacking-s...
b) And this is before Hugging Face agreed to acquired by NVIDIA, supplier to OpenAI?
Can we stop these charades? Maybe circular hacking deals are next?
Folks tend not to go after companies that are just burning cash, but the second they become legit GAAP profitable (if that ever happens) lawyers will be lining up down the block to sue them for any and every mistake these models make.
“Were you harmed by OpenAI’s models? You may be entitled to Compensation. Call 1-800-SUE-AI-BROS” billboards will be everywhere.
This is a worrying part as well. Our tool broke into yours but you can not use our tool to fix it - sorry.
ChatGPT