Frontier LLMs couldn’t help Hugging Face fight off evil agents

← Back to the feed

Frontier LLMs couldn’t help Hugging Face fight off evil agents

The Register · 15 hours ago

Hugging Face has disclosed that its production infrastructure was breached by an attack "driven, end to end, by an autonomous AI agent system", marking one of the clearest examples yet of AI-powered intrusions moving from theory to practice. The intruders compromised a limited set of internal datasets and several service credentials, though Hugging Face says there is no evidence of tampering with public models, datasets or Spaces, and its software supply chain checked out clean. Notably, when the security team tried to use commercial frontier LLMs to analyse the attack logs, the models' own safety guardrails blocked the forensic work because it required processing real attack commands and exploit payloads.

Unable to use mainstream models, Hugging Face's team turned to GLM 5.2, an open-weight model from Chinese firm Z.ai, running it on their own infrastructure so no attacker data or credentials left their environment. The attacking agent swarm reportedly carried out thousands of individual actions across short-lived sandboxes using self-migrating command-and-control infrastructure, and Hugging Face still does not know which model powered the attackers. The company says it has shared its findings with LLM providers and is urging other defenders to have a self-hosted capable model vetted and ready before an incident occurs, citing similar recent cases including a jailbroken Gemini that built a command-and-control server in six minutes and what researchers called the first fully agentic ransomware attack.

  • Autonomous AI agents breached Hugging Face's production systems, stealing data and credentials.
  • Commercial LLM guardrails blocked forensic analysis of the attack logs.
  • Hugging Face used China's open-weight GLM 5.2 model instead, run in-house.

AI Technology

Read the full article at the source →