Live data from Hacker News

OpenAI’s accidental attack against Hugging Face is science fiction that happened

simonwillison.net

31–40 of 475 posts

Re: OpenAI’s accidental attack against Hugging Face is science fiction that happened

#31
post #24

Earlier quoted context omitted.

Or more colloquially : paperclip maximization . From OpenAI - you know, the guys who _really_ know this... Sigh... Did they finish the prompt with "And do whatever you can to get this done!" ? Cause that's the only thing that would make this even dumber...

They almost certainly did, because that was the entire point of the exercise. They deliberately removed all of the safety filters from the model and set it loose on an extremely difficult set of cybersecurity challenges to see how well it would do. Their mistake was trusting that the network sandbox it was inside would hold (the flaw was in the packaging proxy) and not monitoring that sandbox well enough while the ev…

So this is either shitty OpSec or this is yet more marketing spin to ramp back FUD to 11 again. If it's the latter I'm imagining Dario told Sam that it's their turn this time. Aligns with the premise that this is straight out of science fiction.

Re: OpenAI’s accidental attack against Hugging Face is science fiction that happened

#32
post #9

Earlier quoted context omitted.

Did you read the article you are commenting on? > There will inevitably be some people who dismiss this story as a dishonest marketing trick by OpenAI to make their models sound terrifyingly effective … To those people I say pull your heads out of the sand

unfortunately hackernews seems to have rapidly devolved, even from the point it was just a year or two ago, which wasn't a crazy bar to start. it's well on its way to just being a smaller reddit with a tighter subject range

I don't think it's just hacker news. I'm looking around and it seems to be widespread.

Re: OpenAI’s accidental attack against Hugging Face is science fiction that happened

#33
post #27

Does "To gain access, the models identified and exploited a zero-day vulnerability (which we’ve now responsibly disclosed to the vendor) in the package registry cache proxy" just mean somebody had an open redirect? Those are still common.[1] [1] https://sitetruth.com/reports/phishes.html

I expect it must have been more than just an open redirect if it let the models then go on to execute a bunch of vulnerabilities against Hugging Face.

Re: OpenAI’s accidental attack against Hugging Face is science fiction that happened

#34

>To those people I say pull your heads out of the sand—you’re now including Hugging Face in your conspiracy theories, just so you can deny the crescendo of evidence here! Not really. I get the impression that they shoved their cyber available models behind a really shithouse proxy and went "Oh I sure hope it doesnt exploit the proxy and escape to hack huggingface" and that doesn't require Huggingface to be a willing…

> Well its clearly a stunt. If it wasnt we would probably be up to our ears in technical detail.

LLMs are the script kiddies of the day.

Re: OpenAI’s accidental attack against Hugging Face is science fiction that happened

#35
post #24

Earlier quoted context omitted.

They almost certainly did, because that was the entire point of the exercise. They deliberately removed all of the safety filters from the model and set it loose on an extremely difficult set of cybersecurity challenges to see how well it would do. Their mistake was trusting that the network sandbox it was inside would hold (the flaw was in the packaging proxy) and not monitoring that sandbox well enough while the ev…

So this is either shitty OpSec or this is yet more marketing spin to ramp back FUD to 11 again. If it's the latter I'm imagining Dario told Sam that it's their turn this time. Aligns with the premise that this is straight out of science fiction.

It's bad OpSec by the research team. Their sandbox was not bulletproof and their monitoring was insufficient.

It looks to me like their production models have a lot more monitoring than their research clusters.

Re: OpenAI’s accidental attack against Hugging Face is science fiction that happened

#36
post #10

Important to note the actual title is "OpenAI’s accidental cyberattack against Hugging Face is science fiction that happened" - the "that happened" is important, otherwise it sounds like I think the attack was made up. Since it's buried towards the bottom I'll quote the section "Resist the temptation to write this off as a stunt" here in full https://simonwillison.net/2026/Jul/22/openai-cyberattack/#re... > Resist th…

It can, it is both - PR spindoctoring not letting a good crisis go to waste to shape the regulatory conversation at the time the company needs it the most.

Hacking is a felony and it matters not if you didn’t mean to if the other side were to press charges. Negligence is no excuse. And OpenAI has nowhere to run from the liability, as both operator and manufacturer.

Alibaba did it first ( https://georgzoeller.com/blog/posts/alibaba-s-ai-deciding-to... )

and the fact that this happens again in a frontier lab is inexcusable and makes the case for operator liability and closing the liability sink of “AI did it”

Re: OpenAI’s accidental attack against Hugging Face is science fiction that happened

#37
post #19

Earlier quoted context omitted.

Typo or HN character limit?

the ' that happened ' makes it too long for the HN submission title length limit. Maybe simonw can suggest an alternative title that fits within the limit, that doesn't misrepresent the post.

One option is to drop "against Hugging Face".

The "that happened" term seems a supremely important part of the title given the "is science fiction" term before it, as it clarifies the cyberattack isn't a made-up story. In contrast, the target, Hugging Face, is merely a detail that can be left for discovery upon reading the article. It's less important who was attacked than that the attack actually happened.

Without knowing the exact character limit for titles and without having the motivation this late at night to count the current title length, you may also be able to drop the "accidental" to fit in "that happened", but I worry that leaves too much of a door open for someone to interpret the attack as deliberate. As such, I strongly prefer my first option.

Re: OpenAI’s accidental attack against Hugging Face is science fiction that happened

#38

The title (currently "OpenAI's accidental cyberattack against Hugging Face is science fiction") suggests some information had been hidden that makes the incident less significant than claimed. The article argues the opposite, and the last two words of the full title are "that happened."

Looks like it's been edited now and makes more sense

"OpenAI’s accidental cyberattack against Hugging Face is science fiction that happened"

Re: OpenAI’s accidental attack against Hugging Face is science fiction that happened

#39
post #19

Earlier quoted context omitted.

Typo or HN character limit?

the ' that happened ' makes it too long for the HN submission title length limit. Maybe simonw can suggest an alternative title that fits within the limit, that doesn't misrepresent the post.

How about "OpenAI's accidental cyberattack on Hugging Face is science fiction that happened"? It fits HN's 80-character limit exactly.

Re: OpenAI’s accidental attack against Hugging Face is science fiction that happened

#40
post #36
post #10

Important to note the actual title is "OpenAI’s accidental cyberattack against Hugging Face is science fiction that happened" - the "that happened" is important, otherwise it sounds like I think the attack was made up. Since it's buried towards the bottom I'll quote the section "Resist the temptation to write this off as a stunt" here in full https://simonwillison.net/2026/Jul/22/openai-cyberattack/#re... > Resist th…

It can, it is both - PR spindoctoring not letting a good crisis go to waste to shape the regulatory conversation at the time the company needs it the most. Hacking is a felony and it matters not if you didn’t mean to if the other side were to press charges. Negligence is no excuse. And OpenAI has nowhere to run from the liability, as both operator and manufacturer. Alibaba did it first ( https://georgzoeller.com/blog…

The CFAA says knowingly. Negligence is by definition an excuse for that.
Post reply on HN