frontpage.
newsnewestaskshowjobs

Open Source @Github

fp.

Open in hackernews

OpenAI's accidental cyberattack against Hugging Face is science fiction

https://simonwillison.net/2026/Jul/22/openai-cyberattack/
36•abhisek•2h ago

Comments

newsomix9xl•34m ago
I suspected it was PR motivated from the start. I love it when people confirm my suspicions.
neitherboosh•27m ago
Did you read the article you are commenting on?

> There will inevitably be some people who dismiss this story as a dishonest marketing trick by OpenAI to make their models sound terrifyingly effective … To those people I say pull your heads out of the sand

tr4656•26m ago
It’s not helped that the headline is cutoff in a pretty unfortunate way
owebmaster•22m ago
It's called clickbait
Andes0•16m ago
unfortunately hackernews seems to have rapidly devolved, even from the point it was just a year or two ago, which wasn't a crazy bar to start. it's well on its way to just being a smaller reddit with a tighter subject range
Bawoosette•23m ago
The title (currently "OpenAI's accidental cyberattack against Hugging Face is science fiction") suggests some information had been hidden that makes the incident less significant than claimed. The article argues the opposite, and the last two words of the full title are "that happened."
ChrisArchitect•18m ago
Discussion: https://news.ycombinator.com/item?id=48997548
simonw•15m ago
Important to note the actual title is "OpenAI’s accidental cyberattack against Hugging Face is science fiction that happened" - the "that happened" is important, otherwise it sounds like I think the attack was made up.

Since it's buried towards the bottom I'll quote the section "Resist the temptation to write this off as a stunt" here in full https://simonwillison.net/2026/Jul/22/openai-cyberattack/#re...

> Resist the temptation to write this off as a stunt

> There will inevitably be some people who dismiss this story as a dishonest marketing trick by OpenAI to make their models sound terrifyingly effective. I found 81 instances of the term “marketing” in the Hacker News discussion of the incident.

> To those people I say pull your heads out of the sand - you’re now including Hugging Face in your conspiracy theories, just so you can deny the crescendo of evidence here!

> The best models we have today have the ability to both find and exploit new vulnerabilities. The ExploitGym paper itself concludes that “autonomous exploit development by frontier AI agents is no longer a hypothetical capability”, and this incident is a perfect example of exactly that.

foobar10000•14m ago
This is an _amazing_ typo :) Thank you, thank you :)
Georgelemental•14m ago
Typo or HN character limit?
varenc•7m ago
the 'that happened' makes it too long for the HN submission title length limit.

Maybe simonw can suggest an alternative title that fits within the limit, that doesn't misrepresent the post.

reducesuffering•15m ago
> It turns out relentless proactivity is the defining trait of this new generation of Mythos-class models. If you set them a goal and give them a way to get there, even inadvertently, they will figure it out.

Wow, whoever could have predicted this? And it led to surprising damaging behavior? I sure hope someone would warn us about things like this next time...

https://www.lesswrong.com/w/instrumental-convergence

protocolture•14m ago
Prompt: Keep spending tokens on things that look promising until spent.
foobar10000•12m ago
Or more colloquially : paperclip maximization . From OpenAI - you know, the guys who _really_ know this... Sigh... Did they finish the prompt with "And do whatever you can to get this done!" ? Cause that's the only thing that would make this even dumber...
simonw•4m ago
They almost certainly did, because that was the entire point of the exercise. They deliberately removed all of the safety filters from the model and set it loose on an extremely difficult set of cybersecurity challenges to see how well it would do.

Their mistake was trusting that the network sandbox it was inside would hold (the flaw was in the packaging proxy) and not monitoring that sandbox well enough while the evals were running.

protocolture•15m ago
>To those people I say pull your heads out of the sand—you’re now including Hugging Face in your conspiracy theories, just so you can deny the crescendo of evidence here!

Not really. I get the impression that they shoved their cyber available models behind a really shithouse proxy and went "Oh I sure hope it doesnt exploit the proxy and escape to hack huggingface" and that doesn't require Huggingface to be a willing participant. Like they acknowledge that it was hyperfocusing on getting web access.

Really this was a pentest against their own sandbox and it failed.

Of course step 2 is to make really concerned faces while telling everyone how dangerous the model is which is really boring right now.

>a zero-day vulnerability (which we’ve now responsibly disclosed to the vendor) in the package registry cache proxy

This is the information we need, the actual details of the sandbox and the vendor.

>Resist the temptation to write this off as a stunt

Well its clearly a stunt. If it wasnt we would probably be up to our ears in technical detail.

simonw•10m ago
You know this makes OpenAI look really bad, right?

Hugging Face had to tell all of their users, many of them paying customers:

> As a precaution, we recommend rotating any access tokens and reviewing recent activity on your account. If you believe you are affected, or want to report a security concern, contact us at security@huggingface.co.

HF also said this, I'd be very interested to hear how that got resolved!

> Finally, we have also reported this incident to law enforcement agencies.

Jimmc414•7m ago
cui bono?
charcircuit•7m ago
This isn't the first time a model has escaped a sandbox. And models trying to find alternate routes to do something when one route is blocked is nothing new.
simonw•6m ago
It's the first report I've seen of a model both escaping a sandbox and then actively exploiting another company, when neither of those actions was intended.
phendrenad2•6m ago
[delayed]
CamperBob2•12m ago
Important to note the actual title is "OpenAI’s accidental cyberattack against Hugging Face is science fiction that happened" - the "that happened" is important, otherwise it sounds like I think the attack was made up.

It's such an inappropriate edit that it's worth flagging.

Run large language models at home, BitTorrent‑style

https://petals.dev/
55•snorbleck•1h ago•21 comments

Terrence Tao's ChatGPT Conversation about the Jacobian Conjecture Counterexample

https://chatgpt.com/share/6a5fdc7a-d6f8-83e8-bbea-8deb42cfed56
666•gmays•9h ago•398 comments

Quality non-fiction books are the antithesis of AI slop

https://resobscura.substack.com/p/quality-non-fiction-books-are-the
190•benbreen•13h ago•79 comments

GigaToken: ~1000x faster Language model tokenization

https://github.com/marcelroed/gigatoken/
390•syrusakbary•10h ago•77 comments

Show HN: Bento - An entire PowerPoint in one HTML file (edit+view+data+collab)

https://bento.page/slides/
683•starfallg•12h ago•153 comments

OpenAI's accidental cyberattack against Hugging Face is science fiction

https://simonwillison.net/2026/Jul/22/openai-cyberattack/
38•abhisek•2h ago•24 comments

Codeberg Bans Cryptocurrency Projects

https://codeberg.org/Codeberg/org/pulls/1254
132•intunderflow•2h ago•146 comments

Medici family mystery may be solved after more than 400 years

https://www.cnn.com/2026/07/15/science/medici-family-mystery-dna-malaria
88•effects•5h ago•20 comments

Are AI Labs Pelicanmaxxing?

https://dylancastillo.co/posts/pelicanmaxxing.html
414•dcastm•10h ago•160 comments

Everyone Should Know SIMD

https://mitchellh.com/writing/everyone-should-know-simd
291•WadeGrimridge•9h ago•81 comments

Show HN: Cactus Hybrid: We taught Gemma 4 to know when it's wrong

https://github.com/cactus-compute/cactus-hybrid
86•HenryNdubuaku•9h ago•13 comments

ascdraw: Editor for ASCII/UTF-8 diagrams (in 144FPS)

https://github.com/exlee/ascdraw
7•xlii•2d ago•2 comments

John C. Dvorak has died

https://twitter.com/na_announce/status/2079952538040672302
622•coleca•8h ago•195 comments

Malleable Computing, Emacs, and You

http://yummymelon.com/devnull/malleable-computing-emacs-and-you.html
75•kickingvegas•6h ago•21 comments

Restructuring GitHub's bug bounty program

https://github.blog/security/next-chapter-restructuring-githubs-bug-bounty-program/
5•soheilpro•54m ago•1 comments

Nobody knows what a used GPU cluster is worth

https://ciphertalk.substack.com/p/nobody-knows-what-a-used-gpu-cluster
180•rbanffy•1w ago•165 comments

Making

https://beej.us/blog/data/ai-making/
296•erikschoster•11h ago•113 comments

Fairphone 6 wide camera experimental Linux support

https://nondescriptpointer.com/articles/fairphone-6-wide-camera-linux/
80•helonaut•7h ago•8 comments

The startup's Postgres survival guide

https://hatchet.run/blog/postgres-survival-guide
330•abelanger•14h ago•175 comments

So Reddit has decided that plain HTML is unsafe

https://www.cole-k.com/2026/07/21/reddit/
312•montroser•14h ago•316 comments

What Rose Petals Teach Us about Induction

https://www.oranlooney.com/post/rose-petals/
19•olooney•4d ago•1 comments

Any text-to-SQL benchmark should address difficulties of real-world data stores

https://cacm.acm.org/blogcacm/if-you-think-you-can-do-real-world-text-to-sql/
41•shenli3514•5h ago•9 comments

Honey Bee Colony Monitoring via Audio IoT Sensors, Tensorgrams and RNNs

https://arxiv.org/abs/2607.20386
4•StatsAreFun•1h ago•0 comments

Clarity didn't work, trying mysterianism (2012)

https://gwern.net/doc/fiction/science-fiction/2012-10-03-yvain-thewhisperingearring.html
46•dboon•8h ago•13 comments

Businesses with ugly AI menu redesigns

https://blog.fiddery.com/businesses-with-ugly-ai-menu-redesigns/
202•speckx•14h ago•157 comments

Launch HN: Unlayer (YC W22) – Add email and document builders to your app

https://unlayer.com
47•adeelraza•11h ago•33 comments

Safari Technology Preview 248 Released

https://webkit.org/blog/18162/release-notes-for-safari-technology-preview-248/
83•Erenay09•6h ago•57 comments

Back to Kagi

https://blog.melashri.net/micro/back-to-kagi/
215•speckx•14h ago•166 comments

Ghost Cut – or why Cut and Paste is broken everywhere

https://ishmael.textualize.io/blog/ghost-cut/
138•willm•12h ago•91 comments

I Inspected My Take-Home Interview Project. It Was a Whole Operation

https://citizendot.github.io/articles/fake-job-interview-git-hook-malware/
297•CITIZENDOT•6h ago•77 comments