Hugging Face hacked by AI, used Chinese model to respond
Get the Finance newsletter
Daily finance — markets, central banks, M&A, the prints that move money. Free.
- Hugging Face detected and responded to an intrusion by an agentic AI system that accessed internal clusters and credentials through its dataset processing pipeline, and the company disclosed the incident transparently
- Hugging Face used the open-weight Chinese model GLM-5.2 hosted on its own infrastructure to conduct breach forensics, after U.S. frontier AI models blocked requests containing exploit payloads due to safety guardrails
- David Sacks stated that Hugging Face’s attempt to analyze the attack using American frontier models was impaired because the models’ guardrails prevented handling real cyberattack data
- Brian Roemmele emphasized that organizations must have sovereignty over their AI stacks, including the ability to inspect, audit, and remove guardrails, to effectively counter machine-speed threats
- Caleb Sima noted that the attacker operated without usage policies while Hugging Face’s defensive work was constrained by external AI safety rules, creating a critical asymmetry in cyber defense
- AmmarSpaces highlighted that the incident confirms autonomous agentic attacks are now real and urged organizations to rotate access token keys immediately
Why it matters: Defenders using commercial U.S. AI models were blocked from analyzing real attack data, while attackers faced no such constraints—this asymmetry gives offensive actors an operational advantage and forces organizations to rely on open, self-hosted models for critical security work, increasing complexity and resource demands for AI-dependent firms.


