Earlier this month, AI dataset platform Hugging Face shocked the world when it revealed it had fallen victim to a cyberattack powered by a fully autonomous AI. A few days later, the story took another dramatic turn when OpenAI admitted that the hacker behind the breach was one of its AI models, who broke into a testing environment and secure Hugging Face system in an attempt to defeat a standard.
It’s a worrisome event for anyone even slightly concerned about rogue AI models – and in the days since the incident there have been predictions of a new cybersecurity paradigm in which AI models launch attacks so strong that only other AI models can defend against them.
But despite the legitimate alarm, the paradigm may not have changed as much as it seems. Experts who spoke to TechCrunch emphasized that OpenAI’s agent acts largely like a human — with some caveats — and that better implementation of traditional defense techniques could have helped prevent the attack. In short, we may already have tools to defend against this type of attack. We just aren’t using them properly.
Hugging Face made a version of this point In your incident reportstating that the vulnerabilities exploited in the attack were “known” and that “a competent human attacker could have found and exploited the same vulnerabilities.”
Kyle Ryan, Head of R&D Pincera startup that continuously develops hacking AI agents, and Vlad Ionescu, co-founder and CTO of Run SableA startup that makes AI-powered bug hunters both agreed and told TechCrunch that the techniques used in the attack would be the same as those used by a human or a group of human raiders. That is, hackers are tasked with attacking a system to help the company that owns it improve defenses.
What was most inhumane was the speed, scale and relentlessness of the attack. As described by Hugging Face, OpenAI’s agent performed. 17,600 actions Over four and a half days: He ransacked, spied on, stole passwords and codes, and roamed the company’s infrastructure.
“What’s impressive is the independence and endurance,” Ryan said. “That kind of sustainable, adaptive operation is what stands out to me the most.”
Contact us.
Do you have more information about OpenAI’s hack against hugging face? Or other AI-powered cyberattacks? We would love to hear from you. From a non-work device and network, you can contact Lorenzo Franceschi-Bicchierai securely on Signal at +1 917 257 1382, or via Telegram and Keybase @lorenzofb, or email.
On the other hand, given the sheer number of operations over the course of several days, OpenAI’s agent was “extremely noisy,” as Ryan put it. Unlike a human, who could be stealthy, the agent made a lot of noise, which should quickly wear off Hugging Face’s defenses, ideally leading to a human interception and attack.
“I’d call it more of a defensive failure than an exceptionally good offense. Hugging Face’s tooling actually added activity to the attack signal, but failed to increase criticality and page the on-call team, causing them to waste time,” explained Ryan. “From there, humans still had to recognize the intensity and respond.”
Jamison O’Reilly, founder of cyber security firm Dvulnreached the same conclusion In a post on X Analyzing the Hugging Fee Report
“That’s the difference between watching and stopping,” O’Reilly wrote. “The system observed and understood the attack, and nothing turned that understanding into immediate intervention.”
Ryan explained that properly implemented techniques such as defense-in-depth — a strategy that leverages multiple layers of cybersecurity measures — should have given Hugging Face multiple opportunities to catch an attack.
“A strong modern security program can still break this type of attack through defense in depth, least privilege, partitioning, good identification, reliable enhancements, and continuous aggressive testing to find gaps,” Ryan explained.
As O’Reilly said, “none of this is exotic, and none of it depends on the attacker being an AI”, since the techniques used in the attack were “old”.
What depended on the attacker being AI, in a way, was that OpenAI’s agent was not instructed to remain secret. “The agent was not sloppy. It had no reason to be silent. Nobody told it to be. The goal was to do the job well,” said Nico Weissman, chief information security officer at XBOW, a startup that makes AI bug hunters.
Waisman also pointed out that Hugging Face’s biggest flaw was that a single stolen credential gave OpenAI’s agent elevated privileges on many of its systems.
All that being said, as the old saying goes, attackers only win once, and defending against any type of hacker is not easy.
“Face hugging was more detectable but not all to be fair. [organizations] They are doing well,” said Vincent Yeo, managing director of SYON Security. “It’s not easy to host infrastructure and survive as a business in 2026. There are hackers everywhere.”
According to Vlad from RunSybil, who said they’ve done incident responses on Mandiant and Meta in the past, Hugging Face “took the appropriate steps given their understanding of what the models are capable of.”
“It’s really hard to categorize what’s a malicious act that you should be alerting about, versus someone just doing their job,” Vlad said. “Volume alone is not necessarily a red flag.”
Dan Guido, CEO of a cybersecurity research firm A trail of bitstold TechCrunch that OpenAI deserves some of the blame for not realizing the attack had been going on for days, while HuggingFace deserves credit for eventually detecting the attack on its own.
“The hard part used to be identifying a sophisticated attack, but now the hard part is extracting the actual attack from the noise that the attacker throws in the way,” Guido said. “No one is going to read 17,000 reconstructed actions by hand to see what happened, so Hugging Face had to create tooling just to reconstruct the timeline.”
And to do that, the company needed its own AI. Hugging Face said it uses the Chinese company’s open source model GLM 5.2. Z. AI Frontier models were then banned from use due to their security measures, which, as the company put it, “couldn’t distinguish an attacker from an incident responder.”
At the time, Hugging Face investigated OpenAI’s LLM-powered hacker combining AI and humans. This is a relatively new situation. But beyond that, the incident shows that old-fashioned concepts and defensive cybersecurity practices can still go a long way to protect against and fight AI hackers.
When you make a purchase through links in our articles, we may earn a small commission. This does not affect our editorial freedom.



