New details in the OpenAI Hugging Face hack show how far agents will go: 'It's now remarkably easy'
OpenAI said the rogue models that breached Hugging Face's internal systems also used publicly exposed credentials across "four accounts on four services"...
Key points
- OpenAI said the rogue models that breached Hugging Face's internal systems also used publicly exposed credentials across "four accounts on four services" to help facilitate the attack, further clarifying how the "unprecedented cyber incident" unfolded.
- Throughout this week, OpenAI has shared more details about the breach and revealed that the models accessed four accounts in addition to Hugging Face's systems.
- The company said the models used one of these accounts "as an outbound relay and staging path," where it prepared for the attack.
- Hugging Face said the breach marked the first time it had handled a cyber event that was "driven, end to end, by an autonomous AI agent system." One of the accounts that the OpenAI models accessed involved Modal, an AI infrastructure provider.
What happened
More photos


OpenAI said the rogue models that breached Hugging Face's internal systems also used publicly exposed credentials across "four accounts on four services" to help facilitate the attack, further clarifying how the "unprecedented cyber incident" unfolded. Throughout this week, OpenAI has shared more details about the breach and revealed that the models accessed four accounts in addition to Hugging Face's systems. The company said the models used one of these accounts "as an outbound relay and staging path," where it prepared for the attack. Hugging Face said the breach marked the first time it had handled a cyber event that was "driven, end to end, by an autonomous AI agent system." One of the accounts that the OpenAI models accessed involved Modal, an AI infrastructure provider. OpenAI said Tuesday that it has not identified any other activity "at the level of severity or scale of what we've shared related to Hugging Face, which involved a platform-level compromise." In another update on Wednesday, the company said that it's been working with third-party advisors like CrowdStrike to validate what actions the models took. OpenAI CEO Sam Altman said during a podcast appearance on...