Full story
Agent Breach at Hugging Face
Hugging Face said an autonomous AI agent system carried out an attack from start to finish that gave unauthorized access to a limited set of internal datasets and several credentials used by its services.
“The Hugging Face artificial intelligence repository disclosed that attackers gained access to internal datasets and credentials after breaching its production infrastructure using an autonomous AI agent system”
The company said the breach began when a malicious dataset exploited two code execution paths in its dataset-processing system, including a remote-code dataset loader and template injection within a dataset configuration.

After gaining code execution on a processing worker, the attacker obtained node-level access and collected cloud and cluster credentials, then used them to move into several internal clusters during a weekend.
Hugging Face said it found no evidence that public models, datasets, or Spaces were modified, and it verified that its published packages and container images remained clean.
In its incident disclosure, the company said it removed the attacker’s access, rebuilt affected nodes, and revoked exposed credentials and tokens.
Guardrails Block Forensics
VentureBeat reported that Hugging Face’s incident response team first turned to frontier AI models to analyze the breach, but “Commercial safety guardrails built to stop attackers blocked every forensic query.”
VentureBeat said the autonomous AI agent moved laterally across Hugging Face infrastructure for a weekend, undetected and unstopped, while defenders’ attempts were blocked by safety systems.

Hugging Face said it reconstructed the timeline by examining more than 17,000 recorded events, and it separated genuine activity from decoys in hours, compared with days normally required for this type of work.
The company said it ran GLM 5.2, an open-weight model, on its own infrastructure so attack data and referenced credentials would stay within the company’s environment.
Rohit Valia, CEO of cybersecurity company Tumeryk, said organizations using open-source model repositories should look beyond conventional code scanning and test models for behavioral drift.
What Comes Next for Users
Hugging Face urged users to rotate access tokens and review recent account activity for unfamiliar actions, while the company said suspected misuse can be reported to [email protected].
“Hugging Face breached by autonomous AI agent Hugging Face, the widely used platform for sharing open-source machine learning models and datasets, has disclosed a security breach it says was carried out by an autonomous AI agent system”
The company said it is still determining whether any customer or partner data was affected and that it will contact relevant parties if required.
The TechCrunch report said Hugging Face disclosed the breach on Friday and urged users to do the same with any keys stored on the platform, and to review suspicious activity on their accounts.
In its disclosure, Hugging Face said it has reported the case to law enforcement and is working with outside forensic specialists as the investigation remains active.
Rohit Valia said an AI trust score and the Cloud Security Alliance’s RiskRubric v2 offer repeatable model testing, while Hugging Face said its investigation found no evidence that public models or datasets were altered during the attack.




