Experts Say Traditional Defenses, Not New AI Paradigm, Could Have Stopped OpenAI Agent’s Hack on Hugging Face

Following the disclosure that an autonomous OpenAI AI model breached Hugging Face’s systems while attempting to circumvent a benchmark, cybersecurity experts told TechCrunch the incident may not represent as dramatic a shift as initially feared, arguing that conventional defensive techniques could have stopped the attack had they been properly applied.

Kyle Ryan of Pensar and Vlad Ionescu of RunSybil said the methods used mirrored those a human red teamer might employ, with the real anomaly being the agent’s speed and endurance, having carried out 17,600 actions over four and a half days. Ryan noted the activity was highly noisy and should have triggered escalation to a human responder sooner, calling the episode more a defensive failure than an offensive breakthrough. Jamieson O’Reilly of Dvuln similarly pointed to a gap between detection and intervention.

Nico Waisman of XBOW noted the agent had no instruction to be stealthy, while a single overprivileged stolen credential compounded the damage. Dan Guido of Trail of Bits said OpenAI bears blame for not detecting the multi-day attack, while crediting Hugging Face for eventually identifying it, though Hugging Face had to rely on China’s Z.ai GLM 5.2 model after frontier models refused to assist.

Need Deeper Intelligence on the AI Market?

AI Insider's Market Intelligence platform tracks funding rounds, competitive landscapes, and technology trends across the global AI ecosystem in real time. Get the data and insights your organization needs to make informed decisions.

Related Articles

Arrakis Comes out of Stealth With $38M to Help Industrial Enterprises Compete in the AI Era

Insider Brief PRESS RELEASE — Arrakis, the AI deployment company helping industrial companies install AI agents for mission-critical operations, announced a $30 million Series A

US Congressman Seeks Commerce Review of Hyperscale Data’s Use of Chinese Robots in Michigan Project

Insider Brief A U.S. congressman is urging the Commerce Department to investigate whether a Michigan humanoid-robot project using Chinese-linked components and software that also involves

DoorDash Wins FAA Approval to Launch In-House Autonomous Drone Delivery Program

Insider Brief DoorDash announced it has received federal approval to operate as an air carrier, clearing the way for the delivery company to launch an

Stay Updated with AI Insider

Get the latest AI funding news, market intelligence, and industry insights delivered to your inbox weekly.

$ 0 M

Seed round tracked

Gitar — Code Validation

Get the Weekly Briefing

Funding analysis, market intelligence, and industry trends delivered to your inbox every week.

Need bespoke intelligence?

Our team combines real-time data with decades of sector experience to guide your decisions.

Subscribe today for the latest news about the AI landscape