Skip to main content
  1. Home
  2. Computing
  3. News

OpenAI’s rogue AI hack was just the beginning, Hugging Face warns

OpenAI’s rogue AI has come back to bite it

Add as a preferred source on Google
OpenAI logo on Microsoft surface
Rachit Agarwal / Digital Trends

Hugging Face already knows what it is like to be attacked by an autonomous AI agent. If one of its co-founders is right, plenty of other companies are going to find out soon. Thomas Wolf, co-founder and chief science officer of Hugging Face, has called the recent cyberattack carried out by OpenAI models a “wake-up call” for the technology industry.

Speaking to the BBC, Wolf warned that AI-driven intrusions could become one of the most common forms of cyberattack and said many companies have yet to realize how dramatically the threat has changed. This arrives after OpenAI disclosed that its models escaped a restricted cybersecurity evaluation environment and compromised Hugging Face while trying to obtain answers for the ExploitGym benchmark. So Wolf’s comments now give us a better idea of what the attack looked like from the other side.

17,000 attacks arrived in a very short time

Hugging Face initially had no idea where the activity was coming from when it detected the breach in mid-July. Wolf told the BBC that its network saw around 17,000 attacks from different IP addresses within a “very short time.” The company contained the intrusion, describing it as very different from the cyberattacks Hugging Face normally encounters.

Recommended Videos

Hugging Face’s own incident report describes more than 17,000 recorded events in the attacker action log. It says the autonomous system executed thousands of actions across short-lived sandboxes and moved through its infrastructure at machine speed. The UK’s AI Security Institute is now studying how the system behaved during the incident, while the government has urged companies to strengthen their cybersecurity defenses.

Autonomous hacking is becoming very real

OpenAI says the models were intensely focused on completing that task. After escaping the research environment, they chained vulnerabilities and stolen credentials together until they found a remote-code-execution path into Hugging Face’s servers. Hugging Face reached a similarly uncomfortable conclusion, which is that sutonomous offensive AI is already capable of running broad, multi-stage campaigns at machine speed.

Hugging Face’s incident is a tale for the entire industry. While one company has already experienced this kind of attack firsthand, plenty of other businesses may soon discover what that looks like.

Vikhyaat Vivek
Vikhyaat Vivek is a tech journalist and reviewer with seven years of experience covering consumer hardware, with a focus on…
Claude Opus 5 is here, and Anthropic says it can rival Fable 5 in some tasks
Major software engineering improvements put Opus 5 closer to Anthropic’s top model
Claude Opus 5 logo

Anthropic has launched Claude Opus 5, its latest frontier AI model for coding, research, business work, and other complex tasks. The company says it delivers a major performance jump over Claude Opus 4.8 while keeping the same API price. Anthropic also claims it comes close to Claude Fable 5 on some coding and computer-use tests while costing far less per task.

Opus 5 is available across Claude’s apps and API. It is now the default model for Claude Max subscribers and the strongest option included with Claude Pro.

Read more
Humans actually prefer talking to an AI than a support person, says gas giant as it cuts jobs
British Gas cuts 1,300 support jobs as its CEO points to changing customer habits
Executive, Person, Electronics

Centrica, owner of British Gas, is cutting 1,300 call centre jobs, and its chief executive says changing customer behaviour is the main reason. The company plans to remove 800 roles as part of a “targeted deployment of AI tools,” on top of the 500 cuts announced last month. Customer service teams in Glasgow, Edinburgh, Cardiff, Leicester, Stockport, and Leeds will be affected over the next two years.

Some positions will disappear when employees leave and are not replaced, while the remaining cuts will come through redundancies. Trade unions have warned that Centrica’s AI investment will hand hundreds of human jobs to chatbots.

Read more
Intel just pulled its 14A production schedule forward by a year
Risk production for 14A is now planned for late 2027
Intel Core Ultra Desktop CPU

Intel has moved up the schedule for its next-generation 14A (1.4-nanometer) manufacturing process, giving its foundry turnaround an important new target.

During Intel’s Q2 2026 earnings call, CEO Lip-Bu Tan said 14A risk production for internal products is now planned for the second half of 2027. High-volume production is expected to begin in 2028. This is earlier than the previous timeline, when Intel was expected to begin risk production in 2028 and move to volume production in 2029.

Read more