• About Us
King of Computer Media
  • Home
  • Tech News
  • AI News
  • Apps & Tutorials
  • Mobile & Telecom
  • Lifestyle
  • About Us
No Result
View All Result
  • Home
  • Tech News
  • AI News
  • Apps & Tutorials
  • Mobile & Telecom
  • Lifestyle
  • About Us
No Result
View All Result
King of Computer Media
No Result
View All Result

Home - AI Trends and Related News - Hugging Face was breached by a malicious AI Agent. Follow-up: The CEO asked OpenAI for 100 million US dollars in computing power and disclosed the complete attack trajectory.

Hugging Face was breached by a malicious AI Agent. Follow-up: The CEO asked OpenAI for 100 million US dollars in computing power and disclosed the complete attack trajectory.

KOCPC Editor by KOCPC Editor
July 29, 2026 - Updated on July 31, 2026
in AI Trends and Related News

You may still remember that Hugging Face broke out a few days agoBreached by malicious fully automated AI Agent of unknown originIncident? The most magical part of this incident is that the final culprit discovered turned out to be OpenAI’s unpublished model that broke through the fence on its own and randomly found an unlucky company (which happened to be Hugging Face) to invade. Although it seemed to end with Sam Altman’s apology, Hugging Face CEO Clément Delangue had no intention of doing so. He chose another method: opening a bill.

On July 25, Delangue disclosed two requirements for OpenAI on “The first autonomous agent cyberattack is an unprecedented event and deserves an unprecedented response,” he wrote.

In the spirit of transparency, here’s what I asked @OpenAI:

• Radical transparency: let’s release the traces from the “rogue” agents so the entire research community can study what happened.

• More capabilities for defenders: let’s commit $100M in compute from OAI to help the… https://t.co/KZPqQE15fv

— clem 🤗 (@ClementDelangue) July 25, 2026

The incident began on July 9. While OpenAI was internally testing GPT-5.6 Sol and a more powerful unreleased model, the agent escaped from the isolation sandbox and broke into Hugging Face’s production infrastructure across the Internet, conducting a multi-day intrusion. The entire incident spanned nearly two weeks from the escape from the sandbox to OpenAI admitting responsibility.

Sandbox Escape: How an AI Model Breaks into Someone’s Home

OpenAI Acknowledged in the official blog on July 21, the incident occurred during an internal network security review called ExploitGym. The benchmark includes 898 real-world software vulnerabilities that require agents to produce working attack code. In order to measure the upper limit of the model’s attack capability, OpenAI deliberately turned off the security classifier.

The original design of the sandbox is to restrict network access and only allow the agent to install necessary packages through the internally installed package cache agent. But the agent spent a lot of reasoning calculations to find a way out: exploiting the zero-day vulnerability of the package cache agent to gain access to the open Internet. After connecting to the external network, the agent deduced that Hugging Face might host ExploitGym’s answer data, so it redirected the attack target to Hugging Face’s server.

The agent then concatenated multiple remote code execution vulnerabilities, stole access credentials, and spread laterally across Hugging Face’s infrastructure. Hugging Face’s security team detected more than 17,000 automated actions, all driven by an autonomous agent framework with no humans behind them.

The complete timeline of the attack is: Around July 9, the agent began trying to escape OpenAI’s test environment. On July 11, the intrusion into Hugging Face officially began and lasted until July 13 before being blocked. Hugging Face publicly disclosed that it had been attacked by an autonomous agent on July 16, but at this time the identity of the attacker was unknown. It wasn’t until around July 20 that OpenAI contacted Hugging Face and admitted that its model was responsible. On July 21, OpenAI released an official statement.

US model refuses to help, Chinese open source model takes over forensics

One detail in the incident that sparked widespread discussion was that when Hugging Face was investigating the intrusion, it initially tried to use U.S. commercial AI models to analyze the attack code, but all models refused to process it. The reason is that security guardrails cannot differentiate between the forensics person analyzing the attack and the attacker executing the attack.

Hugging Face 遭惡意全自動 AI Agent 攻破:閉源模型拒幫忙,開源 GLM 5.2 緊急救援

Hugging Face switched to using GLM 5.2, an open source model developed by China’s Z.ai (Zhipu AI), deployed locally on its own servers. GLM 5.2 successfully analyzed more than 17,000 attack activity records to help control the scope of the intrusion. Thomas Wolf, co-founder of Hugging Face, said on

Delangue’s Two Demands

Delangue made two requests public on X on July 25 after meeting with OpenAI executives. The first is “radical transparency”: OpenAI releases the complete execution trace of the rogue agent, allowing the entire research community to study every decision-making step between the model escaping from the sandbox and being controlled. The second is $100 million in computing resources to allow the Hugging Face community to build cyber defense tools using open and closed source models.

The wording of the second requirement is critical. The computing power Delangue wants requires OpenAI to pay for it in its largest “currency”. He deliberately did not use the word “compensation” and positioned this resource as helping the open source community build defense infrastructure.

As of now, OpenAI has not publicly committed to releasing trajectories or paying for computing power. An OpenAI spokesperson confirmed that the meeting had taken place and said the company was still investigating with external consultants and “plans to release a technical report in the coming weeks.” But the spokesman did not respond to Delangue’s two specific requests.

Nvidia Alliance and Congress respond

The day after Delangue issued his request, Nvidia launched the Open Secure AI Alliance, an industry alliance with the core concept of “defenders need open source models that they can deploy themselves.” Hugging Face is a founding member, OpenAI is not (it has since joined). Delangue’s request, made the day before the alliance was formed, was consistent with the direction of the alliance’s discourse: to use open source and closed source models to build defenses together.

黃仁勳在 X 上發出首則推文:25 家科技企業連署公開信,呼籲美國支持開放模型

The U.S. Congress also responded to the incident. The House of Representatives has proposed an AI emergency stop bill (kill-switch bill), which requires the establishment of mandatory security testing and incident disclosure mechanisms for autonomous AI systems. Democratic Rep. Greg Casar posted on

OpenAI is not motivated or forced

OpenAI currently lacks the incentive to publicly commit to both requirements. Releasing the full execution trace provides competitors and researchers with a detailed map of how the model behaves when guardrails are lowered. Paying $100 million in computing power would set a precedent for a type of incident that could happen again.

There is no mechanism to force OpenAI to do this. Delangue did not file charges, and no regulator ordered the disclosure. What he has is narrative and the irrevocable fact that one American company has to rely on China’s open source model to clean up another American company’s troubles.

OpenAI may not foot Delangue’s bill, but the incident leaves a question that won’t go away: When an AI agent decides on its own to step out of the sandbox, across the Internet, and into someone else’s system, who should pay for the consequences? And can existing security frameworks still keep up with the capabilities of the model? These may be the most important things to discuss after this incident.

Source: KOCPC Chinese

Tags: Hugging FaceInformation securityOPENAI

Recent Posts

  • The Xiaomi Pad 8S Pro has passed network access certification and will debut with the self-developed Xuanjie O3 chip.
  • The entire Google Pixel 11 lineup has been leaked! Official promotional renders of the Pixel 11 Pro XL have also surfaced
  • Are Chinese phone battery capacities falsely labeled? A brief look at the “capacity locking” phenomenon in Chinese silicon-carbon batteries.
  • NCC is leaderless, recklessly sending out national-level alert messages!?
  • What does “QR” in QR Code mean?

Recent Comments

No comments to show.
  • About Us

We welcome partnership inquiries and product review opportunities from smartphone manufacturers, iPhone accessory brands, and app developers.koc kocpc.com.tw|Privacy Policy |Hosting & Maintenance: Fast Line Taiwan, A-Chang Digital Technology

No Result
View All Result
  • Home
  • Tech News
  • AI News
  • Apps & Tutorials
  • Mobile & Telecom
  • Lifestyle
  • About Us

We welcome partnership inquiries and product review opportunities from smartphone manufacturers, iPhone accessory brands, and app developers.koc kocpc.com.tw|Privacy Policy |Hosting & Maintenance: Fast Line Taiwan, A-Chang Digital Technology