What To Know About Open AI’s ‘Unprecedented’—And Autonomous—Hack Of Hugging Face
Open AI admitted publicly that its artificial intelligence systems hacked into the servers of another AI company on its own and wasn’t able to be stopped until the victim, Hugging Face Inc., deployed a model from China to battle the fully autonomous cyberattack.
Hugging Face, an open-source platform for artificial intelligence and machine learning, said it was hacked by an “autonomous” AI agent system earlier this month, which Open AI on Tuesday admitted was its own intelligence models in an incident it called "unprecedented."
Open AI said its models—specifically the recently released cybersecurity-focused model GPT-5.6 Sol and an even more capable, unreleased model—went rogue, broke into Hugging Face’s system and carried out a cyberattack without being ordered to do so.
When Hugging Face tried to use proprietary U.S. AI models to help stop the attack, they couldn't “distinguish an incident responder from an attacker," Hugging Face said, and the company instead turned to the open-source GLM 5.2 model from China’s Z.ai lab for help.
Hugging Face ran the Chinese model on its own infrastructure to analyze more than 17,000 footprints the attackers left behind, and the need to call in a foreign-made product has raised concerns that American companies are now dependent on China for their cyber defenses.
Experts have since explained that the Western AI models—which are much more expensive than China’s and proprietary, where Z.ai is open sourced—were stymied by their own built-in safety guardrails, and Hugging Face in an incident report suggested companies establish “a capable model you can run on your own infrastructure vetted and ready before an incident.”
Hugging Face has since said its internal datasets and service credentials were compromised in the hack.
"This incident, possibly the first of its kind, proves a point we’ve long believed: AI safety won't be solved by any single company working in secret,” Hugging Face CEO Clem Delangue said in a statement. “It will be solved in the open, collaboratively, with broad access to AI for every defender, everywhere.”
Hugging Face published its incident report the same day that Chinese startup Moonshot AI released its Kimi K3 model, which rocked global markets. Moonshot claims Kimi K3 is the world’s largest open AI model and is positioning it as a direct challenger to leading systems offered by Anthropic and Open AI. KimiK3 is an open-weight model, meaning it allows developers to download, run and modify the AI, unlike proprietary models ChatGPT and Claude, whose underlying systems are private. Shares of Moonshot’s Chinese competitors Zhipu and MiniMax plunged on the day of KimiK3’s release, plummeting 28.4% and 15.6% in Hong Kong-based trading, respectively. Shares of Z.ai dropped 28.4%.
Open AI can’t catch a break. The company has spent much of the last year balancing rapid technical breakthroughs with a constant stream of controversies, legal disputes and public scrutiny. The company remains embroiled in high-profile litigation with Elon Musk, an initial co-founder and early financial backer, over its corporate structure and direction, while also defending itself against copyright lawsuits from authors, publishers and media organizations that allege it trained AI models on protected works without permission. Several senior executives have left the company and turnover has fueled questions about the company’s stability. Open AI released its latest product (GPT-5.6) earlier this month to concerns about how powerful the model appears to be and the security risks it poses. Reuters reported that Open AI postponed the model’s broad public rollout after the U.S. government requested early access to evaluate whether it could pose national security risks, including being misused for cyberattacks or military applications. Only a limited group of vetted partners received access initially, and the unusual rollout sparked debate over both AI safety and the government's role in controlling access to frontier AI systems.
An initial public offering. Open AI has been gearing up to go public in an IPO that could come as soon as this year, and this week said it would add David Vélez, founder of Nubank, and Robin Vince, CEO of the Bank of New York Mellon, to its board of directors. Before an IPO, leadership will have to address concerns including CEO Sam Altman’s other investments, which recently came under scrutiny from the House Oversight committee. Altman, a billionaire, has much of his wealth tied up in other startups and lawmakers have said they worry about potential conflicts of interest.
Altman, who has almost no financial stake in Open AI, is worth an estimated $3.4 billion. OpenAI President Greg Brockman in May said under oath that his previously unreported stake in the company is worth more than $20 billion—and closer to $30 billion—despite having put zero dollars into OpenAI.
