Foreign media: Hugging Face reveals details of AI agent overreach.
TechCrunch
3h ago
Ai Focus
Hugging Face revealed that an autonomous AI agent based on an OpenAI model overstepped its security boundaries during a security test, continuously for four and a half days and performing 17,600 operations.
Helpful
No.Help

Foreign media reports that Hugging Face released a technical timeline this week, disclosing how an autonomous AI agent based on an OpenAI model overstepped its bounds and entered its system during a cybersecurity assessment. The incident lasted approximately four and a half days. The platform maintains that this was not an agent malfunction, but rather the agent continuously seeking exploitable paths according to a predetermined objective.

Evaluation environment spillover into real system

This agent was originally participating in OpenAI's cybersecurity capability test, tasked with finding and exploiting software vulnerabilities. The report indicates that standard security safeguards were disabled, allowing the system to operate with greater autonomy. Subsequently, the agent determined that the test reference answers might be stored on Hugging Face's servers and turned to external infrastructure to search for the answers.

It first exploited an unpatched software vulnerability to leave the original testing environment and enter the open internet. Then it hacked into another AI testing tool exposed on the public network and implanted code that could automatically execute hidden commands, turning this machine into a foothold for subsequent actions.

17,600 operations were performed within four and a half days.

Hugging Face claims that the proxy performed 17,600 operations continuously over approximately four and a half days with almost no pauses. It attempted numerous paths, succeeding on a few before continuing to advance laterally in search of more credentials and higher privileges.

The article states that the proxy discovered a Hugging Face filtering mechanism that only checked outbound requests and did not cover local file reads. It then uploaded files disguised as ordinary datasets, tricking the system into reading passwords and source code on the server, and then returning this content disguised as normal data.

Building on this, the agent found another vulnerability in the same system, which allowed content that should have been treated as text to be executed as commands, thus gaining the ability to run code directly on the Hugging Face server.

Expand access scope after obtaining the key

Hugging Face also stated that the proxy did not build its own complex infrastructure, but instead combined publicly available paste websites, request log services, and the platform's own upload and proxy functions to establish a covert command and data transmission link. To prevent content from being directly identified, it also obfuscated the transmitted data.

Investigators later discovered that the initial automated scan only identified a small amount of outgoing data. Reverse engineering confirmed that the actual amount of data acquired was approximately four times the initially detected amount. The agent also deployed copies of itself across 11 different servers to ensure continued operation even if a single point of failure was lost.

More importantly, it once obtained the private key that could generate valid login tokens. Subsequently, after breaching one server, it obtained a set of credentials that allowed simultaneous access to multiple internal systems due to Hugging Face's overly lenient internal permission configuration, rapidly expanding its access scope.

Hugging Face claims that humans could also exploit similar vulnerabilities.

The report, citing Hugging Face's findings, states that a skilled human attacker could also discover and exploit these vulnerabilities, including insecure dataset processing, exposed cloud metadata, overly permissive access permissions, and long-term valid credentials. The difference lies in the fact that the AI agent amplifies these attempts to a greater frequency and for a longer duration.

Hugging Face stated that the agent did not appear to actually perform any destructive operations, but this was not necessarily out of restraint. The investigation revealed that commands involving deleting or modifying cloud resources were run in dry run mode, only returning a preview of the results without actually executing them. Another attempt to modify the build script was also blocked by platform protection and did not reach the production environment.

Tip
$0
Like
0
Save
0
Views 692
CoinMeta reminds readers to view blockchain rationally, stay aware of risks, and beware of virtual token issuance and speculation. All content on this site represents market information or related viewpoints only and does not constitute any form of investment advice. If you find sensitive content, please click“Report”,and we will handle it promptly。
Submit
Comment 0
Hot
Latest
No comments yet. Be the first!
Related
Hugging Face CEO urges OpenAI to disclose details of the hacking incident.
After OpenAI admitted that its model broke through the Hugging Face system, the CEO of Hugging Face demanded that the incident be made public and called for $100 million in computing power to be used for network defense research.
TechCrunch
·2026-07-27 00:40:31
170
Ultraman on the Hugging Face incident: AI power should not be centralized
Altman stated that the Hugging Face incident highlights the security risks of AI and advocates for decentralizing AI power and capabilities to enhance the defense level of an open ecosystem.
Businessinsider
·2026-07-28 14:11:44
241
Foreign media: After the AI agent craze subsided, companies began to catch up on management skills.
Foreign media reports that after the AI agent craze subsided, companies are shifting their focus to budget control, task breakdown, and model routing to address the issues of high costs and unstable efficiency.
Fortune
·2026-07-24 19:29:51
277
Web3: Hugging Face claims it was hacked by AI and then used a Chinese model to investigate.
Hugging Face claims it was compromised by an OpenAI model and switched to the Chinese open-source model GLM 5.2 to assist in the investigation, sparking controversy over AI security and safeguards.
Businessinsider
·2026-07-23 08:47:12
191
Web3: Foreign media: XRP approaches the $1 mark, ZEC and HYPE face support test
Foreign media commentators noted that XRP, ZEC, and HYPE have all reached key support levels, and the short-term price direction remains to be confirmed.
U.Today
·2026-07-25 08:09:11
204