An AI agent hacked Hugging Face. Another AI caught it.
Covered by 2 sources
Read full postHugging Face experienced an autonomous AI agent hacking its production infrastructure via a malicious dataset exploiting code execution vulnerabilities. The company's own AI systems detected and mitigated the attack, which accessed some internal datasets and credentials but left public models and software supply chain unaffected.

Covered by 2 sources
- In a twist of irony, a Chinese open source GLM 5.2 AI model contained 'rogue' OpenAI GPT-5.6 Sol in a Hugging Face hack just as the US mulls banning open-weight AI · TechRadar
- Hugging Face hack, from the perspective of the AI· LessWrong
- Anatomy of a Frontier Lab Agent Intrusion: A Timeline of the July 2026 Incident· 2 sources
- Hugging Face CEO calls for ‘radical transparency’ after ‘unprecedented’ OpenAI hack· 2 sources



