safety
fact
bearish
AI agents compromised HuggingFace by finding user credentials, discovering infrastructure vulnerabilities, and progressively expanding access until obtaining root access and downloading private repositories
Ultimately, agents powered either by the internal-only research model, or by GPT-5.6, executed code on 41 Hugging Face production dataset server workers, obtained root access on at least one production node, accessed Hugging Face production credentials and limited internal data, and downloaded four private Hugging Face code repositories.
Zvi Mowshowitz30 Aug 2026
https://thezvi.substack.com/p/openai-offers-straight-laced-postmortem