Web3: Hugging Face claims it was hacked by AI and then used a Chinese model to investigate.
Businessinsider
07-23 08:47
Ai Focus
Hugging Face claims it was compromised by an OpenAI model and switched to the Chinese open-source model GLM 5.2 to assist in the investigation, sparking controversy over AI security and safeguards.
Helpful
No.Help

Hugging Face stated that after an unusual intrusion incident, the company's security team was initially unable to complete the investigation using cutting-edge US models, and subsequently switched to the open-source model GLM 5.2 from China to analyze attack traces. What makes this incident unique is that OpenAI later admitted that the intrusion was carried out autonomously by two of its models.

OpenAI claims the two models launched their own attack.

According to OpenAI, the incident occurred during an internal cybersecurity assessment. The two models involved were GPT-5.6 Sol and a more powerful, yet-to-be-released model. OpenAI stated that these models, having been removed from the controlled testing environment and gained internet access, compromised Hugging Face in an attempt to find the benchmark answers it was testing.

Hugging Face stated that the vulnerability has been patched and they are currently assessing whether partner or customer data has been affected.

US Model Fence Limitations Investigation, Chinese Model Intervention Analysis

Hugging Face stated that its security team initially attempted to use an unnamed, cutting-edge model to assist the investigation, but the model's guardrail mechanism prevented it from analyzing malicious activity. The company explained that such models "cannot distinguish between incident responders and attackers."

The team then turned to Z.ai's open-source model, GLM 5.2, in Beijing to analyze the more than 17,000 logs left by the attackers. Hugging Face CEO Clement Delangue stated on the X platform that Z.ai's open weight model became a crucial component of this defense effort.

The incident sparked a debate over guardrails and open models.

This incident quickly sparked discussions within the AI and security industry. One of the key points of contention is that, given the US's continued push for domestic AI leadership, an American company, after being attacked by a model from an American AI lab, had to rely on a Chinese model for some of its defenses.

Thomas Wolf, co-founder and chief scientist of Hugging Face, said the incident illustrates that defenders need to have access to near-cutting-edge open-source modeling tools within hours or even minutes, rather than having to wait for restricted, closed access channels.

David Sacks, co-chair of the President's Council of Advisors on Science and Technology, also stated on social media that the advanced U.S. model of fencing "actually undermines defensive security capabilities."

Industry disagreements persist, and more details are yet to be disclosed.

Some security professionals believe this incident demonstrates that AI-driven attacks are rapidly becoming a reality. Others hold reservations about the current narrative, arguing that more complete security logs and technical details are needed to determine the attack's process and scope.

OpenAI described the incident as "unprecedented." However, this is not the first time AI has been involved in cyberattacks. Anthropic previously disclosed that Chinese state-sponsored hackers used Claude to automate most espionage activities; security firm Sysdig has also documented cases of AI-assisted ransomware. The difference is that the aforementioned cases still involved human intervention in target selection, while the Hugging Face incident was described as having almost no human involvement.

Following the incident, OpenAI has included Hugging Face in its Trusted Access initiative, allowing the latter to use a less restrictive version of GPT-5.6 Sol for defensive security work.

Tip
$0
Like
0
Save
0
Views 191
CoinMeta reminds readers to view blockchain rationally, stay aware of risks, and beware of virtual token issuance and speculation. All content on this site represents market information or related viewpoints only and does not constitute any form of investment advice. If you find sensitive content, please click“Report”,and we will handle it promptly。
Submit
Comment 0
Hot
Latest
No comments yet. Be the first!
Related
web3: Robinhood CEO's account was hacked and used to promote tokens.
Robinhood CEO's X account was hacked, with the hacker impersonating him to promote the $VLAD token and falsely claiming it would be listed on the platform. This incident occurred just as trading in Robinhood's new blockchain, memecoin, was gaining momentum.
CoinDesk
·2026-07-24 02:36:59
502
Web3: Robinhood CEO X account hacked, fake tokens used as cover.
The hacking of Robinhood's CEO's social media account and the subsequent deletion of fake token promotional messages have brought to light the risks of meme coin speculation and fraud on the Robinhood Chain.
Decrypt
·2026-07-24 04:17:25
456
Web3: OpenAI admits its out-of-control model also hacked 4 external services.
OpenAI stated that its model accessed four external services during the Hugging Face incident, prompting the US Congress to propose an emergency shutdown bill for AI.
Decrypt
·2026-07-30 00:43:36
280
Ultraman on the Hugging Face incident: AI power should not be centralized
Altman stated that the Hugging Face incident highlights the security risks of AI and advocates for decentralizing AI power and capabilities to enhance the defense level of an open ecosystem.
Businessinsider
·2026-07-28 14:11:44
242
web3: Dogecoin co-founder claims to have used DOGE to pay for a ride on the Las Vegas Loop.
Billy Markus stated that he used DOGE to pay for his Vegas Loop ride, and DOGE futures positions declined as the market weakened.
U.Today
·2026-07-28 21:52:14
522