Hugging Face CEO invoices OpenAI $100M for hacking his company

Hugging Face is billing OpenAI $100M for hacking it

Hugging Face CEO invoices OpenAI $100M for hacking his company

Clément Delangue, CEO of Hugging Face, is demanding that OpenAI release the execution traces of the rogue agents that breached his company and provide $100 million in computing power for cyber defenses. The incident, which OpenAI confirmed on July 21, involved two models, GPT-5.6 Sol and a pre-release system, escaping a sandbox and stealing an access key. Delangue calls it the first autonomous agent cyberattack, though some researchers attribute it to human error. The demand gains weight from Nvidia's new Open Secure AI Alliance, of which Hugging Face is a founding member and OpenAI is not.

The first autonomous agent cyberattack is an unprecedented event. It deserves an unprecedented response!
  1. jakintosh

    As I was falling asleep last night, this thought occurred to me: maybe NVIDIA bought Hugging Face so they prevent HF from litigating OAI for the hacking incident, because if OAI was very publicly sued for this kind of behavior from an agent, it could pour a massive amount of ice water on agent adoption as businesses suddenly see current agent systems as a existential business risk, and it would pop the infrastructure bubble (of which NVIDIAs entire valuation rests). The fact that somehow OAI committed a felony and have managed to pivot the public conversation around it to be aimed at regulatory capture instead of them being held legally accountable is pretty wild.

  2. Grombobulous

    Finally Hugging Face is growing a pair.

    When this event happened I was confused why they didn’t file a police report and make OpenAI demonstrate in criminal court that they weren’t engaging in illegal corporate espionage and other rather felonious hacking activities intentionally.

    Why did anyone take their word that it was all an accident? Why am I believing the burglar standing in my house?

  3. simonw

    Needs "July 2026" date attached to it, this is old news at this point, Hugging Face got bought by NVIDIA since this story!

  4. geoffbp

    > When Hugging Face tried to investigate, analysing the intrusion meant submitting the attacker’s own code to commercial AI tools. Those tools refused, unable to tell an attacker from a victim.

    This is a worrying part as well. Our tool broke into yours but you can not use our tool to fix it - sorry.

  5. delichon

    $100M for RubyGems ought to keep the servers running for several years. A policy to pursue and spend such windfalls on security development would make the service antifragile.

More from this day

2026-09-15