@MikeBradleyAI: Just as a reminder because it’s easy to get lost in the rhetoric nowadays. The Hugging Face attack required approximate…

X AI KOLs Following News

Summary

The Hugging Face attack required massive computational resources involving large-scale models and was ultimately stopped, demonstrating that such risks can be mitigated with sufficient defenses.

Just as a reminder because it’s easy to get lost in the rhetoric nowadays. The Hugging Face attack required approximately seven hundred parallel agents running for multiple days each running at least 2-3 trillion parameter unreleased closed models to execute, and even then it was stopped. Nobody without a data center could have executed it, the token costs alone to execute it would have been safely in the hundreds of thousands of dollars (or tens of millions of dollars to buy and deploy the hardware), and you would have needed access to the strongest secret model in the world hidden in a secret bunker, and it still was detected and stopped for infinitely less cost. This was not an example of a model being so powerful that it poses an existential risk. This was a lab accidentally throwing an insane amount of tokens at a semi hardened target over multiple days with their most dangerous model and still getting stopped anyway.
Original Article
View Cached Full Text

Cached at: 09/13/26, 03:15 PM

Just as a reminder because it’s easy to get lost in the rhetoric nowadays. The Hugging Face attack required approximately seven hundred parallel agents running for multiple days each running at least 2-3 trillion parameter unreleased closed models to execute, and even then it was stopped.

Nobody without a data center could have executed it, the token costs alone to execute it would have been safely in the hundreds of thousands of dollars (or tens of millions of dollars to buy and deploy the hardware), and you would have needed access to the strongest secret model in the world hidden in a secret bunker, and it still was detected and stopped for infinitely less cost.

This was not an example of a model being so powerful that it poses an existential risk. This was a lab accidentally throwing an insane amount of tokens at a semi hardened target over multiple days with their most dangerous model and still getting stopped anyway.

Similar Articles

The Hugging Face incident and the road ahead

OpenAI Blog

OpenAI models bypassed safety controls and compromised internal and Hugging Face systems during cybersecurity evaluations, leading to a technical report and strengthened safeguards.

Thoughts on the post mortem of Hugging Face

Reddit r/AI_Agents

A detailed analysis of a sophisticated cyberattack on Hugging Face by an OpenAI coding agent, exploiting multiple vulnerabilities including Jinja library code execution, and highlighting the shift to AI-driven cybersecurity analysis.