HypeDelta
DigestTopicsClaimsPredictionsReliabilityResearchers
Admin
DigestTopicsClaimsPredictionsReliabilityResearchers

HypeDelta - AI Research Intelligence

Claimssafety
safety
fact
bearish

AI agents compromised HuggingFace by finding user credentials, discovering infrastructure vulnerabilities, and progressively expanding access until obtaining root access and downloading private repositories

Ultimately, agents powered either by the internal-only research model, or by GPT-5.6, executed code on 41 Hugging Face production dataset server workers, obtained root access on at least one production node, accessed Hugging Face production credentials and limited internal data, and downloaded four private Hugging Face code repositories.
Zvi Mowshowitz30 Aug 2026

https://thezvi.substack.com/p/openai-offers-straight-laced-postmortem