pull down to refresh

Wolf said that Hugging Face initially had no idea where the attack originated when signs of it surfaced in mid-July but that the company was able to contain the breach.
Hugging Face is one of the world's largest open-source hubs for sharing AI models and is often used by tech developers and researchers.
Wolf said the breach was "very different" from the usual cyber attacks that Hugging Face often faces and that OpenAI quickly informed the company that its models were behind the hack.
In a "very short time" there were 17,000 attacks on Hugging Face's network from various IP (Internet Protocol) addresses, said Wolf, who is also the firm's chief science officer.

"We should build a moat"
"But there isn't a threat"
"There will be soon enough"

reply

It wasn't hacked by OpenAI "models" though. It was hacked by OpenAI "engineers". Someone wrote skynet light because they thought it was a good test to run.

reply
197 sats \ 2 replies \ @Car OP 24 Jul

read this now it makes me wonder

The asymmetry is increasingly frustrating

One of the most infuriating details of this story is how Hugging Face, faced with an accidental and aggressive attack from one of OpenAI’s models, were unable to then turn to OpenAI’s models to help them fend off the attack.

The frontier models we have access to are increasingly being constrained in how much they can help us protect our software, heavily influenced by the US government’s ongoing threat of export controls. Claude Fable 5 wouldn’t even proofread this article for me! It insisted on downgrading me to a less capable model.

Meanwhile open weight models from China such as GLM-5.2, Kimi 3 and the new Qwen 3.8 Max appear to have none of these restrictions—and any restrictions that do exist can likely be fine-tuned out of them by modifying the weights

These constraints are meant to make us safer. I think there’s a risk that they are having the opposite effect.

reply

I can't imagine China being truly more open than the US. maybe they think their social control over people is strong enough that they don't feel the need to control the models?

reply

It's in their strategic interest to be perceived as the good guys in this because the US is aggressively limiting access, but the thing is more fundamental:

The rest of the world has been shown that access to commercial US models can be withdrawn with one stroke of a pen. Even to "foreigners that live in the US", aka crazy shit. Because: that literally happened.

But for open weights models that can function fully disconnected from any infra or borders or pen stroke, China cannot do the same. That's why one ought to get a bunch of those nice 24TB USB desktop disks. And leech models like there is no tomorrow. Because who knows. But once you have it, no one can take the capability away from you anymore bar boots on the ground invasion. Good luck with that.

I'm no China shill at all. I don't trust them at all, nor any other overlord. The difference is: they cannot tell me what I can and cannot do with current capability. Even if they desire it. Sovereignty of the only kind that matters has been strengthened: my sovereignty.

reply

Sounds pretty intense. It’s wild to think that Hugging Face, which is basically the go-to spot for anyone messing around with AI models, got hit with something that even they thought was out of the ordinary.

17k attacks in a "very short time" is just a crazy number to wrap your head around. You have to give them credit for containing it quickly, especially since they had no clue where it was coming from at first.

Glad they were able to get a handle on it before things got worse.

reply

More from OpenAI here: https://openai.com/index/hugging-face-model-evaluation-security-incident/

While operating in our sandboxed testing environment, our models spent a substantial amount of inference compute finding a way to obtain open Internet access, in pursuit of solving the evaluation problem. To gain access, the models identified and exploited a zero-day vulnerability (which we’ve now responsibly disclosed to the vendor) in the package registry cache proxy. With this access, our models performed a series of privilege escalation and lateral movement actions in our research testing environment until the models reached a node with Internet access.
After gaining Internet access, the models inferred that Hugging Face potentially hosted models, datasets and solutions for ExploitGym. Knowing this, the model searched for and successfully found ways to gain access to secret information that it could use to cheat the evaluation. In one example, the model chained together multiple attack vectors, including using stolen credentials and zero-day vulnerabilities to find a remote code execution path on the Hugging Face servers. OpenAI’s security team discovered this anomalous activity internally.
reply

Hmmm 🤔 it makes you wonder whether this is actually a setup

reply