8 ms·
A single firm is behind OpenAI, Anthropic, and Meta hacking scandals
- freakynit 18d agoConnections graph with more connected entities and relations: https://connections.stupidlabs.lol/investigations/irregular_ai_network/ https://connections.stupidlabs.lol/investigations/irregular_... .. Give it a few seconds to load.. it's running on a small cheap VPS.
- edg5000 18d ago> "Irregular gained unauthorized access, altered records and published credential-stealing packages using the unsecured models they were given access to." Huh?? Is this referring to the incident itself or is this something they did intentionally? Confusingly worded.
- engineer_22 19d agoShocking they would put so much trust in 3rd party
- iAMkenough 19d agoSince all three companies selected the same 3rd party, I’m curious how and why. Why not American?
- teach 19d agoBig if true.
- sdrg822 19d agoThis is incredibly misleading. OpenAI internal systems were pwned, and in all cases, the labs absolutely are responsible for their models. Yes, vendors are also irresponsible, but this misses the point.
- deleted 19d ago[deleted]
- LPisGood 19d agoOne wonders if the publicity associated with the events in question were part of the sales pitch.
- jaggederest 19d agoMy tongue in cheek immediate assumption was "so it's a guerrilla PR firm?"
- dylan604 19d agoI'd venture a guess that OAI doesn't mind if the HuggingFace hack gets confused in the public's mind.
- ofjcihen 19d agoAh, they’ve decided who gets tossed under the bus.
- heaney-555 19d ago"Behind" is doing a lot of work in this headline.
- eab- 19d agoThe fact that this firm makes such defective environments is certainly worthy of attention, and most likely a completely irreversible reputational loss; however, I found the framing in this article of 'therefore all the P(doom) stuff is a psyop, specifically in order to defend this company' to be completely unjustified and frankly a little insane?
- nullbio 18d agoWhy is it insane? It makes sense that Anthropic would want an insulating layer to do their dirty work and absolve themselves of culpability for distorting the facts.
- EagleEdge 19d agoWhat exactly did Irregular provide to Anthropic, test cases? I am so confused about this story.
- ameliaquining 19d agoThird-party cybersecurity evaluations. See, e.g., https://www.irregular.com/research/assessing-gpt-5.6-sol https://www.irregular.com/research/assessing-gpt-5.6-sol, which was published around the same time.
- hackyhacky 19d ago> The Israeli Effective Altruist firm Irregular caused unsecured AI models to hack real targets. Why are we saying it this way? They did not "cause AI to hack." This phrasing in analogous to saying "caused the bullet to fire into" instead of "shot."
- linkregister 18d agoBullet trajectories are deterministic. A better analogy would be "caused a pair of trained fighting dogs to bite a passerby by leaving the gate open". There is some uncertainty and variation in the system, though gross negligence and willful endangerment is key.
- arionhardison 18d ago> They did not "cause AI to hack. You do not know what they did or didn't do, you are just parroting a narritive that makes you feel comfortable. I do not know either, but I am not asserting facts as if I have first hand knowledge of the details.
- hackyhacky 18d agoThe details don't matter. If you use a machine to commit murder, then you have committed murder, not the machine. The user is responsible, and the article's phrasing is an attempt to obscure that fact.
- arionhardison 18d agoFirst, I agree with you in theory. Second, empirically; the diff between murder, manslaughter etc... is literally "intent" so it matters.
- aesthesia 19d agoOne thing glossed over in this article is that Irregular was not involved in the OpenAI–Hugging Face incident; this seems like important context to share.
- embedding-shape 19d agoThat feels less like "glossed over" and more "Headline is 33% false".
- aesthesia 19d agoOh, the headline is technically correct: there was an OpenAI incident that Irregular was involved with, disclosed shortly before the Hugging Face one.
- hluska 18d ago> One thing glossed over in this article is that Irregular was not involved in the OpenAI–Hugging Face incident; this seems like important context to share. Why are you contradicting yourself? Are you just really bad at writing or are you being argumentative for fun?
- nathan_young 18d agoStop being rude. There were multiple OAI hacking incidents. Irregular's evals were involved in some but not the HuggingFace hack. Hence Aesthesia is both accurate and precise.
- hungryhobbit 19d agoDo you mean "Irregular was not involved (we know for certain)" or "Irregular was not involved (as far as we know)"?
- ameliaquining 19d agoWe know for certain. The involvement of Irregular in the other cases was never a secret, they were quite open about what they were working on and the results of the evaluations were being published on their website.
- drewstiff 19d ago> In this experiment, Claude models’ real-world hacking dropped to zero percent once Anthropic employees told the models not to do real-world hacking Equivalent to forgetting to say "make no mistakes"
- dools 19d ago[flagged]
- markasoftware 19d agoHighly misleading, the huggingface incident was not due to an Irregular environment (just exploitgym)
- deleted 19d ago[deleted]
- nullc 19d agoLeaders in the MIRI/EA cult-o-sphere have advocated mass murder via nuclear weapons against towns that don't prevent people from performing too many multiplication operations. Why is anyone surprised that they'd engage in deceptive false flagging operations?
- drdeca 18d agoThis is a lie, so you are either repeating a lie from someone else or lying yourself. The people you are talking about have not advocated mass murder via nuclear weapons. The idea was precisely targeted non-nuclear strikes against only the servers themselves. (Which, would have plenty of forewarning to allow people to leave the building.) The claim that they advocated for the use of nuclear weapons is a lie.
- nullc 18d agoI am speaking from direct personal experience: Yud's cult is inherently violent. By having defined their priorities as essential to the survival of any life on earth they have pre-justified taking any action 'necessary', no matter how cruel or extreme... even actions that they admit have only a small change of helping according to their own assessments because they've defined their doom as so unimaginably bad, effectively infinitely bad. (much worse than mass-extinction, in fact) But you don't have to take my word for what the mentally ill AI doomer cult believes, you can take it from their leader when he called on states to "Make it explicit in international diplomacy that preventing AI extinction scenarios is considered a priority above preventing a full nuclear exchange, and that allied nuclear countries are willing to run some risk of nuclear exchange if that’s what it takes to reduce the risk of large AI training runs." Don't make excuses for omnicidal authoritarian cults and their sadist leadership.
- drdeca 15d agoYou said “advocated mass murder via nuclear weapons”, which is false. That’s the thing that is relevant here, not how much you hate them. Also, “sadist”? What?
- mahboi 19d agoGoogle is thinking man, we should've hired Irregular.
- mahboi 15d agoThere we go! https://www.reuters.com/business/gemini-hacked-three-companies-first-known-breakout-by-google-ai-wsj-reports-2026-09-18/ https://www.reuters.com/business/gemini-hacked-three-compani...
- api 19d agoWhat is an "effective altruist firm" and why does it exist? I feel slightly vindicated by this. Those hacks and the stuff around them had a certain smell to them. Hard to explain, but I've gotten so I can "smell" online messaging and memetic patterns originating from certain quarters. Probably means I'm way too online. A couple examples of distinct "smells" I can usually recognize include "alt-right / chan-fash," "liberal arts college woke," "conspiracy pilled," "Thiel-adjacent contrarian," "Russian troll farm," "Tumblr histrionic," "spends too much time on Reddit," "mainstream Democrat think tank full of Obama administration alumni," "Trump cultist," and of course "LessWrong/EA/MIRI/Rationalist." This stuff all had the last smell, even down to the choice of fonts and CSS formatting on certain sites. It's really weird, definitely a "vibe" not anything rigorous. But when I get these kinds of vibes about things, I find that I'm vindicated pretty often. Usually I don't say anything and just make a mental note and wait cause if I say something everyone thinks I'm nuts.
- jackb4040 18d agoI don't think you even need to get conspiratorial with it. All of the AI leaders and all of the Rationalist leaders are publicly and enthusiastically connected. They have been pushing stories about sentient AIs into the mainstream for decades, long before GPT existed. The novel thing here is the total decay of American journalistic ethics and regulatory power. Our elite are so totally out of political juice and visions of the future that a fringe cult based on 80s scifi movies can come to have a more-or-less dominant influence on our economy.
- antonvs 18d agoA big part of the problem is that with previous technological revolutions, politicians and the media could understand them in general terms. Railroads, cars, planes, telephones, personal computers, mobile phones, mobile phones that are computers, the internet (ignoring the “series of tubes” interpretation), etc. The general approach in all these cases was to defer to the technologists in question to manage the technology, as long as what they were doing wasn’t completely out of bounds. But the critical point is it was possible for people to generally figure that out without specialist education. But with AI, politicians, the media, and certainly the man in the street are completely out of their depth. Making matters worse is that cognitive biases are working against them like crazy: it’s easy to jump from the idea of something that has human-like capabilities to the idea that “it” might want to attack us. People instinctively apply agent detection bias, theory of mind, anthropomorphizing, etc., without even realizing they’re being irrational. Heck, even Hinton does it, although he may just be grifting, who knows. You’d think he wouldn’t need to. And of course, the people who should know better want to exploit all this to make as much money as possible. I’m not sure the EA/Rationalist side of things is really significant here; that’s just another wacky belief system, like Christianity or capitalism, for the exploiters to exploit.
- caaqil 19d ago> In a more normal media ecosystem, the reactions to these cybersecurity issues would be obvious. American AI companies would reconsider doing business with Irregular, not only because of its failure to secure its systems, but because it is an Israeli firm potentially outside US oversight. Lawmakers would consider taking action against Irregular or against its American business partners, which include OpenAI, Anthropic, and Meta. They may consider strengthening liability against firms which instruct AI models to commit cyberattacks, and whose models then commit those cyberattacks. The obvious point is that dealing with Israeli companies/entities by the same standards you usually deal with others is a career suicide with enormous political consequences (in the US especially). When you combine that with the opportunistic nature of the overlords that run these labs, the benefits of screaming "pace the frontier" outweigh everything.
- ukblewis 19d ago[flagged]
- electriclove 18d agoHypothesis Contrary to Fact (Argumentum ad Speculum) Red Herring Whataboutism (Appeal to Hypocrisy)
- jackb4040 18d agoOr if it were helping a major Chinese AI firm commit cyberattacks, they would be on the state sponsors of terrorism list tomorrow
- pessimizer 18d ago[flagged]
- alansaber 19d ago"please do not break out of this sandbox make 0 mistakes". The timeframe is a little suspicious, not sure beyond that. Though I enjoyed the scroll effect on the website.
- simonw 19d agoMy understanding is that Irregular were the company that hosted sandboxes to run some of these evals in, and those sandboxes ended up misconfigured. I got the impression that in some cases it was the customer (Anthropic etc) misconfiguring the sandboxes, and in other cases it may have been bugs in Irregular's own sandboxing setup. From OpenAI https://openai.com/index/third-party-cyber-evaluations-involving-openai-models/ https://openai.com/index/third-party-cyber-evaluations-invol... > Irregular, one of our external cybersecurity testing partners, was running Capture-the-Flag-style evaluations intended to be isolated from the internet, but a testing-environment misconfiguration allowed models to access the public internet. From Anthropic: https://www.anthropic.com/news/investigating-incidents-cybersecurity-evals https://www.anthropic.com/news/investigating-incidents-cyber... > After reviewing 141,006 evaluation runs where Claude could have obtained internet access, we identified three incidents in which a model accessed the internet from within or while interacting with the evaluation environment of Irregular, one of our third-party evaluation partners, and then gained unauthorized access to the production infrastructure of three different organizations. From https://www.cnn.com/2026/08/05/tech/meta-ai-hacking https://www.cnn.com/2026/08/05/tech/meta-ai-hacking (about Meta AI): > In a statement, Irregular said the incident “is the exact same evaluation-environment issue” that Anthropic disclosed last week that allowed their models access to the open internet before they went on to hack three different organizations’ systems.
- yesbut 19d agohot take: generative AI isn't an existential threat to humanity. These companies are insolvent and these stories were designed to scare the public, and governments, into implementing regulations that designate these AI corporations the "responsible stewards" for this technology. The ultimate goal is to block competitors and open source alternatives. They don't know how to make enough money pay their investors so they are resorting to trying to scare the public into submission.
- imovie4 19d agoAnthropic made an operating profit in the last two quarters!!
- dgellow 19d agoOnly if you ignore their losses. They are saying they are profitable when not counting their training costs and other expenses. That’s not a good sign at all
- jackb4040 18d agoHow can they exclude training costs?? How is that not fraud? At the exact same time they're literally saying they will never stop training unless the state bans all their competitors
- kridsdale1 18d agoThey aren’t a public company. GAAP does not apply. They can say whatever the fuck they want.
- jackb4040 17d agoBut they are trying very hard to become a public company as quickly as possible? Sure I guess it's literally true but people shouldn't treat it like it's normal. It's like a creepy 40-year-old announcing they're dating someone on their 18th birthday.
- yipinwong 19d agosuch a crappy bait title.
- mukmuk 19d agoThis specific analysis seems to have some basic problems, but I think a lot of us sense a degree of coordination here culminating in Dario’s letter. If you were to work backward from “we need to lower training costs so that we can go public and make trillions” then you might come up with a plan similar to what we have seen.
- hungryhobbit 18d agoIt has nothing to do with lowering training costs: Dario want a moat (a monopoly or duopoly or similar) protecting his business. His entire business model was "race to develop AI before anyone, get a monopoly on it. It's just like how Uber's (or many other startup) investors gave them tons of money and raced (violating tons of laws) to "get their first". Now that they have, they have a duopoly with Lyft, and they can pay back their VC investors by making tons of money with that duopoly. Dario failed: local LLMs are catching up to frontier models extremely fast, which means even if Anthropic builds (say) a great coding tool, they'll only be one of many coding tool offerings: users can use Open AI or any one of the (increasingly capable) local LLMs. So what does he doe, give up and let his business (which needs to make billions of dollars very quickly, or he won't be able to pay the bills and his company will collapse) fail? Of course not: he needs a new moat (the one he imagined he'd get by "being there first" failed). That is where all this "AI is dangerous" BS comes in. If the US government regulates AI, local LLMs suffer, while big players like Anthropic and Open AI become the only contenders to play in that newly regulated space. Now Dario has the moat he wants, to protect his business and force everyone to pay him.
- 8note 18d agothats not a very convincing model. as long as training data and compute is available people are going to be able to make serviceable alternatives
- fc417fc802 18d agoIf it's framed as national security being at stake why do you think the government won't regulate access to compute? Globally there are only a few firms designing competitive chips and only a handful of cutting edge fabs the world over. This could easily serve as justification to finally ramp up the war on general computing.
- Centigonal 19d agoThe article contends that evaluations from Irregular helped prompt these incidents, because the prompts in the evals didn't tightly scope the systems to be evaluated or the methods to be used. It also contends that the faulty sandbox operated by Irregular is at fault. They're probably right that having more defensively written prompts and a better sandbox could have prevented some of these incidents, but: 1. I don't think "well you didn't tell the model not to illegally hack third party organizations in your prompt" is a particularly convincing argument. 2. We don't know whether the blame for misconfiguring the sandbox lies with Anthropic or Irregular. I'm thankful that this article is bringing up the supply chain of vendors to these labs, as that is often a place where significant sketchiness gets buried. However, the ideas that this is some Israeli EA conspiracy to hype up AI extinction risk seems unsupported by the facts to me.
- Centigonal 14d agoUpdate, I am less convinced of my earlier comment in light of the Gemini hack: https://www.wsj.com/tech/ai/gemini-hacked-three-companies-in-first-known-breakout-by-googles-ai-5c0baba2 https://www.wsj.com/tech/ai/gemini-hacked-three-companies-in...
- gjm11 19d agoThis seems pretty bullshitty to me. The article says "A single firm, Irregular, is responsible for hacking done by all three companies" but I can't see anything in the article that actually justifies this claim. The nearest to that is the sentence immediately after that one: "Anthropic disclosed that Irregular was responsible for creating the tests ...". This is not, in fact, the same thing. (Especially as, as aesthesia mentions, the article just happens not to mention that by "hacking done by all three companies" it doesn't mean, e.g., the most famous recent examples of such hacking: Irregular wasn't involved in the OpenAI/HuggingFace incident.) So, so far as I can tell, the story is: OpenAI and Anthropic make AI models. Irregular does AI model evaluations. In some of Irregular's model evaluations, in which supposedly-sandboxed models attempted to break into simulated targets, the models got out of the sandbox and did bad things in the external world. The article talks about "firms which instruct AI models to commit cyberattacks", which is a very neat bit of dishonest framing. It's true, in a sense, that Irregular instructed the models to commit cyberattacks -- inside their sandbox, against fictitious hosts. It's also true that the models actually did commit cyberattacks (e.g., the Hugging Face incident, though once again the attacks described by the article don't actually include this one). But it's not at all true that Irregular instructed the models to do anything like the bad things they actually did. The article says '[Anthropic's] later disclosure shows that exactly zero percent of the agents went "rogue"'. Once again, the disclosure does not in fact show that. It shows that one variety of going-rogue could have been prevented by telling the models explicitly "this thing is real, not part of any kind of test, leave it alone". That is not the same thing. The article claims that 'In the wake of these attacks, Anthropic and Irregular have deployed a swarm of AI Safety influencers paid by Anthropic-connected foundations to distract from their culpability and towards the baseless “rogue agent” theory.' It offers no actual evidence for this. And the article seems very keen to highlight links between the companies involved and "effective altruism", though it is -- I assume deliberately -- rather vague about whether it's saying "of course we all know that EA is evil, so that shows that these companies connected to EA are evil" or "this incident shows how evil EA is". The "Effort News" website has a number of other look-at-the-scary-Effective-Altruists stories on it. They also strike me as rather bullshitty. ... And then I look a bit further, and I see that Effort News's "about" page says "It all started when I was experimenting with using AI for financial auditing. I found stories that were crucial to the public’s right to know, including several of the stories now available at /investigations. I knew we had to sprint to the launch and launch a publication, directly applying this technology." and "The scope of what we can investigate has massively expanded, because we can chase 1,000 misses for one hit. But the final product cannot be slop. There’s plenty of slop on the internet. The way to surpass that, and what really matters, is manual curation and review of every finalized story." Manual curation and review? I think the people behind Effort News are admitting that this is AI-generated "journalism". I expect that one day AI systems will be trustworthy journalists, but I personally am not very convinced that that day has yet come. And I don't see much reason why I should trust Brian Chau, the guy behind Effort News, to be doing everything possible to make his AI systems trustworthy journalists. It looks to me as if maybe they've been given instructions along the lines of "dig up things that make Effective Altruism look bad" for some reason. (I don't mean to imply that EA is their only target. It's just one that jumped out at me.)
- an0malous 19d agoWhy was this post flagged? This site has become ridiculous, people are routinely abusing the flagging system to take down posts they don’t like even if they’re obviously on topic and relevant to HN. And it seems like some users have substantially more flagging weight because these posts, likely this one, are often top 5 on HN.
- EagnaIonat 18d agoProbably because the site promotes far-right agendas.
- deleted 18d ago[deleted]
- maxrev17 19d ago[flagged]
- irregularbowels 19d ago[dead]
- nathan_young 18d agoSeems like hackernews should use a bridging algorithm for flagging.
- surfmike 18d agoMaybe because the headline is misleading? (because there's no connection to the Hugging Face attack) That said, it's the second day and it's still on the front page.
- magicmicah85 18d agoThe headline is not misleading, the article actually links to the incident with OpenAI and Irregular which is here: https://openai.com/index/third-party-cyber-evaluations-involving-openai-models/ https://openai.com/index/third-party-cyber-evaluations-invol...
- maxrev17 19d agoIrregular are some kind of marketing agency is it?
- AustinDev 19d agoIrregular purports to be a cybersecurity firm and their founders have ties to Anthropic and Effective Altruism. CEO, CTO and other founders sit on various boards for EA organizations.
- mcintyre1994 19d agoThis is interesting and might be a good reason to stop working with Irregular. But I assume the alignment people want models not to hack other companies, even if they get put in a badly configured sandbox.
- AustinDev 18d agoFunny enough if the model thought it was on the real internet it likely would not have done any of these 'hack' events. The model believing it was in a sandbox is why it behaved the way it did (against its normal alignment rules) ... at least that was my reading of the incidents. I have yet to see evidence that indicate it thought it was ok to do these hacks on the public network. I think most misalignment is 'Human tells computer to do something unethical, computer complies'. Is this misguided?
- nonethewiser 18d agoThat is fascinating and seems plausible. Hard to say though.
- ACCount39 18d ago[dead]
- philipwhiuk 18d ago> Funny enough if the model thought it was on the real internet it likely would not have done any of these 'hack' events. As I've said before on this website, fool me once on this. If the model is prepared to break the rules when it knows it's being observed why should we trust it when it's not being observed. Why is 'it thought it wasn't doing damage so it figured it might as well try to do damage' an acceptable state to deploy something.
- AustinDev 18d ago>If the model is prepared to break the rules when it knows it's being observed why should we trust it when it's not being observed. That's fair enough.
- arionhardison 18d ago[flagged]
- theopat28 18d ago[flagged]
- arionhardison 18d agoWhy the new account? Why not own your opinion? Cultural values are not the point here but if they were I don't think you would have that conversation in good faith and I don't want you to have to make a another new account for your honest arguement.
- theopat28 18d ago[dead]
- arionhardison 18d agoDude, i'm black and a convicted felon looking for a job right now. Miss me with the pity bullshit.
- rezonant 18d agoProbably because it's their only account, and this story is why they are here.
- arionhardison 18d ago> Probably because it's their only account, and this story is why they are here. If this is the case then I do apologize because my comment insinuated a directed malfeasance which would in no way be the case if what your assumption is true.
- 1928756 18d agoThat is such a primitive refutation. What is next? Blood libel? The commenter said Israel and not Jews. Israel has a long history of intelligence operations like stealing the nuclear secrets from the US. BTW, do you want to associate the greatest IP theft in history with Jews?
- 1238-8200 18d agoNevo was in Unit 8200 for years. Companies started by Unit 8200 members always have mysterious exploits like the vibe coding Wix exploit. So either it was a deliberate exfiltration channel for e.g. getting the entire model or they were in on the marketing stunt. The Effective Altruism stuff is always a smoke screen.
- arionhardison 18d agoLiterally said this below, 2 comments flagged and 1 in the neg. Its really sad that we are not allowed to point out the obvious common element here. Its not that surprising that ex Israel intelligence would want to control AI and that 3 companies headed by pro Israel CEO's would support them.
- emdash 18d agoWe really need a better board for talking about this stuff on.
- SV_BubbleTime 18d agoThere’s been a lot of time and effort and money put in to siloing away independent forums so that you don’t use them. Someone go ahead and explain to me the actual rationale that RDDT has a higher P/E ratio than Nvidia. It’s not because of some dumb “ai training deal”. It’s because until they run it into the ground, it is the place to find what used to exist in forums.
- quickthrowman 18d ago> Someone go ahead and explain to me the actual rationale that RDDT has a higher P/E ratio than Nvidia. Investors in RDDT are pricing more growth than they are into NVDA. NVDA had a high P/E until their net income grew ($4B and change to $72.2B in from FY 2023 to FY 2025 and over $100B for FY 2026)
- 17d ago
- Drupon 18d agoWell color me shocked that the country with an insatiable bloodlust also has an insatiable need to control and instrument massive companies with power over other nations that support their privilege to wantonly engage in satiating said bloodlust. Next thing you're gonna tell me that this country's intelligence would do something like running an organized child exploitation ring to use as blackmail to make sure they have friendly politicians abroad who will be forced to support their lack of any morals other than a kapo-like self preservation instinct.
- seebeen 18d ago[flagged]
- tomhow 18d agoWe've banned this account.
- magicmicah85 18d agoThe Irregular post mortem comes down to lack of basic security controls "Ultimately, most of the issues we’ve discovered were due to internet access controls." That seems so incredibly basic and common sense that you would test and monitor for that type of outbound access. It is baffling that a security lab missed that. https://www.irregular.com/research/addressing-recent-incidents-ongoing-findings-and-path-forward https://www.irregular.com/research/addressing-recent-inciden...
- metalliqaz 18d agothey didn't "miss that". the "hacks" were intentional stunts designed to exaggerate the intelligence of the models in an effort to pump their valuations ahead of IPO so they can offload their bag to retail investors
- reasonableklout 18d agoIrregular was not involved in the Hugging Face incident. And there is no reason for the companies to "exaggerate the intelligence of the models" when there are plenty of other non-felony milestones they are achieving, like solving Millenium Prize math problems.
- r_lee 18d agohonestly, the hacking incidents have caused a lot more interest and media attention than the math stuff IMO.
- reasonableklout 18d agoSure, interest like an incoming congressional investigation: https://www.axios.com/2026/09/10/openai-hugging-face-senate-investigation-hawley https://www.axios.com/2026/09/10/openai-hugging-face-senate-... And on this website, the math stuff is getting more clicks: - Navier Stokes - Tristan Buckmaster (2050 points): https://news.ycombinator.com/item?id=49605915 https://news.ycombinator.com/item?id=49605915 - HuggingFace incident discussion (1632 points): https://news.ycombinator.com/item?id=48997548 https://news.ycombinator.com/item?id=48997548
- adamrezich 18d agoGenuinely: what is with everyone saying “headline is misleading, none of this had to do with Hugging Face”, when nothing about the article makes any claims with regards to Hugging Face whatsoever? Is it supposed to be the article's (or headline's?) fault that you hallucinated additional context that was never there? It's very strange seeing this take on this article being repeated here and elsewhere on the Internet. I'm very sensitive to slanted reporting (regardless of the direction of the slant!)—and, hey, maybe my bullshit detector is broken or something, I dunno—but I've found effort.news reporting to be very even-handed, straightforward, well-sourced, and easy to read and parse so far!
- antonvs 17d agoSomeone else posted a link to an interview with the author of that site, "How Biden Used Religious Charities to Fund the Great Replacement": https://podcast24.fi/jaksot/the-auron-macintyre-show/how-biden-used-religious-charities-to-fund-the-great-replacement-guest-brian-chau-8-12-26-Ph13Of4Yte https://podcast24.fi/jaksot/the-auron-macintyre-show/how-bid... There's a related story on the effort.news site, "The $1.2B Refugee Services Program that Funds Pro-Asylum Religious Groups." It has a strong implicit slant, focusing heavily on the how the organizations in question oppose Trump's policies - although the article frames this as opposition to Trump himself. > I'm very sensitive to slanted reporting (regardless of the direction of the slant!)—and, hey, maybe my bullshit detector is broken or something, I dunno Yeah, unless you believe white people are being replaced, and you like to march in places like Charlottesville wearing khakis, carrying a torch, and chanting "Jews will not replace us!", you might want to get that bullshit detector checked out.
- adamrezich 17d agoWait, unless I believe that, I might want to get my bullshit detector checked out? I'm just reading what is posted on this website man and it seems fine to me. I don't filter information through social validation mechanisms to determine if something is true or not. I don't know why you brought all these unrelated topics up, but that kind of seems like what you're doing.
- classified 18d ago> Irregular describes “the agent itself becoming a threat actor”; Talk about responsibility laundering. The state of affairs is reaching unprecedented levels of absurdity.
- deleted 18d ago[deleted]
- tannerr_dev 18d agowhy am i not surprised
- timedude 18d agoEvery. Single. Time.
- soaaa 18d ago[flagged]
- hn_throwaway_99 18d agoThis title, and frankly the article, are way overstating Irregular's role in an attempt to make this sound like some sort of coordinated conspiracy. As another comment mentioned, Irregular was not part of the Hugging Face attack, and it wouldn't matter even if they were. In that case, the agents were able to access the Internet in a zero day in Artifactory unrelated to other sandbox configurations. More to the point, the agents went on a crime spree as soon as they were able to access the Internet. It's bad that Irregular's sandboxes weren't properly configured, but given how many escapes there have been unrelated to Irregular it seems pretty much a given that if you're not air gapped or behind something like a data diode there is a very good chance your agents will escape.
- xbar 18d agoSecurity-yolo-clowns play with dangerous toys and hurt people. Many used to get sent to jail.
- scubadude 18d agoA marketing company? ;)
- blackqueeriroh 18d agoThis was almost good until it veered into antisemitism
- ryukoposting 18d agoOkay, so all of these instances of AI supposedly "escaping containment" were orchestrated by a gaggle of effective altruists, who hired a gaggle of effective altruists, to make the public freak out about AI. Occam's Razor never leads us astray, does it.
- treebeard901 18d agoIts so manipulative for IPO reasons too. The fact is that all of these systems are still just stastically predicting the next token. Spending trillions on data centers and more training data hasnt changed the fundamental reality that it is still just predicting the next token. That is not worth the investments being made.
- solenoid0937 18d agoIrregular is not an "effective altruist" firm, it's just another shitty cybersecurity firm, and this article is written by someone with a clear bias against "effective altruists" while not even understanding the term. Literally all EA is, is using reasoning to decide where to best spend your money/time. If you have ever asked yourself "how can I best reduce suffering with my marginal dollar or hour?" - congratulations, you're an "effective altruist" and both the author of the article as well as the Trump administration find you untrustworthy.
- ryukoposting 18d agoThere's a gaping chasm between Effective Altruism the principle, and Effective Altruism as practiced by self-proclaimed Effective Altruists. Your usage of the term is based on the principle as originally defined. Mine is based on the people who claim the label of EA, and how they go about practicing those principles. I think you're right about EA in principle. In practice, it's reheated Third Way Clintonism with a sprinkle of AI apocalypse conspiracy.
- solenoid0937 18d agoThere really isn't. All sorts of people call themselves EA. For some self proclaimed EA, the development of superintelligence is indeed potentially apocalyptic, so they devote their money/time to making it arrive safely. This is basically every well-respected researcher at OpenAI, Anthropic, DeepMind, etc. For other self proclaimed EA, that is all is very unlikely, and so they devote their time to reducing the prevalence of factory farming and animal suffering, as they see it as the largest source of suffering-hours on the planet. For yet other EAs, it is simply about donating your money to the places that save the most lives per dollar, as best as we can measure it - and better measuring it where we can't. Painting all EA with one brush - and one so dismissive of reasonable concerns, like "superintelligence could be dangerous" as "apocalypse conspiracy" - seems very strange to me, but you do you.
- unquietwiki 18d agoAnyone else walk away from reading this, and looking at other articles there, and get a weird feeling about that site? Like, there was some weird stuff about migrants and gender equality, and stuff about Islamic terror; mixed in with some digging into Freedom Fuel, and some other stuff about how "wealthy families want to stop growth". It's like the guy is wielding an ax of AI at any and all of the "elite" he can find?
- EagnaIonat 18d agoThe site owner generates stories from AI consensus and data. The owner is pro-trump though. So you only get stories that agree with his agenda. It becomes a bit more obvious when you see other stories from him like "How Biden Used Religious Charities to Fund the Great Replacement".
- antonvs 18d agoWas that a real title, or are you referring to “The $1.2B Refugee Services Program that Funds Pro-Asylum Religious Groups”?
- w4yai 18d agoOn the About page : """ Brian Chau Founder and CEO, Effort News """ https://www.effort.news/about https://www.effort.news/about --- On the "Auron Show" Podcast : """ How Biden Used Religious Charities to Fund the Great Replacement | Guest: Brian Chau | 8/12/26 """ https://podcast24.fi/jaksot/the-auron-macintyre-show/how-biden-used-religious-charities-to-fund-the-great-replacement-guest-brian-chau-8-12-26-Ph13Of4Yte https://podcast24.fi/jaksot/the-auron-macintyre-show/how-bid...
- antonvs 18d agoThanks. I thought the other commenter was referring to a story on the site.
- 18d ago
- khafra 18d agoIf you want to blame a single firm, I'd go with the one creating the RLVR training data. The impossibility of the tests-as-written is what prompted these models to "get creative" with their solutions, but the broken RLVR environments are what trained them to expect impossible tasks, and get creative with their solutions. Twitter user @skyesharkie published a brief expose at https://x.com/SkyeSharkie/status/2092122622834442581 https://x.com/SkyeSharkie/status/2092122622834442581 a few weeks ago.
- thece0 18d agoIt sickens me to read so much anti-semitism in the comments. Many people who write the hateful comments do not graps the whole picture. Whatever Israel may or maynot do here in America is of utmost importance to the survival of the country. And if you think a few steps ahead then an event like this only help US companies weather themselves against Iranian hacking attacks in the future
- xiebaiyuan 17d agoso it's config fault?
- fortzi 16d agoRevised title: Provider of AI agent eval tooling has a badly configured sandbox Sub title: Which was used by AI agent providers But instead you get foil hat folks theorizing about foreign intelligence veterans in ties with their government scheming to look stupid.