Live data from Hacker News

OpenAI’s accidental attack against Hugging Face is science fiction that happened

simonwillison.net

1–10 of 475 posts

OpenAI’s accidental attack against Hugging Face is science fiction that happened

#1
OpenAI and Hugging Face address security incident during model evaluation - https://news.ycombinator.com/item?id=48997548 - July 2026 (1121 comments)

OpenAI’s accidental attack against Hugging Face is science fiction that happened
simonwillison.net

Re: OpenAI’s accidental attack against Hugging Face is science fiction that happened

#3

[flagged]

Did you read the article you are commenting on?

> There will inevitably be some people who dismiss this story as a dishonest marketing trick by OpenAI to make their models sound terrifyingly effective … To those people I say pull your heads out of the sand

Re: OpenAI’s accidental attack against Hugging Face is science fiction that happened

#4

[flagged]

Did you read the article you are commenting on? > There will inevitably be some people who dismiss this story as a dishonest marketing trick by OpenAI to make their models sound terrifyingly effective … To those people I say pull your heads out of the sand

It’s not helped that the headline is cutoff in a pretty unfortunate way

Re: OpenAI’s accidental attack against Hugging Face is science fiction that happened

#5
The title (currently "OpenAI's accidental cyberattack against Hugging Face is science fiction") suggests some information had been hidden that makes the incident less significant than claimed. The article argues the opposite, and the last two words of the full title are "that happened."

Re: OpenAI’s accidental attack against Hugging Face is science fiction that happened

#6
post #4

Earlier quoted context omitted.

Did you read the article you are commenting on? > There will inevitably be some people who dismiss this story as a dishonest marketing trick by OpenAI to make their models sound terrifyingly effective … To those people I say pull your heads out of the sand

It’s not helped that the headline is cutoff in a pretty unfortunate way

It's called clickbait

Re: OpenAI’s accidental attack against Hugging Face is science fiction that happened

#8

The title (currently "OpenAI's accidental cyberattack against Hugging Face is science fiction") suggests some information had been hidden that makes the incident less significant than claimed. The article argues the opposite, and the last two words of the full title are "that happened."

[deleted]

Re: OpenAI’s accidental attack against Hugging Face is science fiction that happened

#9

[flagged]

Did you read the article you are commenting on? > There will inevitably be some people who dismiss this story as a dishonest marketing trick by OpenAI to make their models sound terrifyingly effective … To those people I say pull your heads out of the sand

unfortunately hackernews seems to have rapidly devolved, even from the point it was just a year or two ago, which wasn't a crazy bar to start. it's well on its way to just being a smaller reddit with a tighter subject range

Re: OpenAI’s accidental attack against Hugging Face is science fiction that happened

#10
Important to note the actual title is "OpenAI’s accidental cyberattack against Hugging Face is science fiction that happened" - the "that happened" is important, otherwise it sounds like I think the attack was made up.

Since it's buried towards the bottom I'll quote the section "Resist the temptation to write this off as a stunt" here in full https://simonwillison.net/2026/Jul/22/openai-cyberattack/#re...

> Resist the temptation to write this off as a stunt

> There will inevitably be some people who dismiss this story as a dishonest marketing trick by OpenAI to make their models sound terrifyingly effective. I found 81 instances of the term “marketing” in the Hacker News discussion of the incident.

> To those people I say pull your heads out of the sand - you’re now including Hugging Face in your conspiracy theories, just so you can deny the crescendo of evidence here!

> The best models we have today have the ability to both find and exploit new vulnerabilities. The ExploitGym paper itself concludes that “autonomous exploit development by frontier AI agents is no longer a hypothetical capability”, and this incident is a perfect example of exactly that.

Post reply on HN