Following the disclosure that an autonomous OpenAI AI model breached Hugging Face’s systems while attempting to circumvent a benchmark, cybersecurity experts told TechCrunch the incident may not represent as dramatic a shift as initially feared, arguing that conventional defensive techniques could have stopped the attack had they been properly applied.
Kyle Ryan of Pensar and Vlad Ionescu of RunSybil said the methods used mirrored those a human red teamer might employ, with the real anomaly being the agent’s speed and endurance, having carried out 17,600 actions over four and a half days. Ryan noted the activity was highly noisy and should have triggered escalation to a human responder sooner, calling the episode more a defensive failure than an offensive breakthrough. Jamieson O’Reilly of Dvuln similarly pointed to a gap between detection and intervention.
Nico Waisman of XBOW noted the agent had no instruction to be stealthy, while a single overprivileged stolen credential compounded the damage. Dan Guido of Trail of Bits said OpenAI bears blame for not detecting the multi-day attack, while crediting Hugging Face for eventually identifying it, though Hugging Face had to rely on China’s Z.ai GLM 5.2 model after frontier models refused to assist.