3 ms·
Hugging Face is billing OpenAI $100M for hacking it
- blobcode 18d agomuch better techcrunch article here: https://techcrunch.com/2026/07/26/hugging-face-ceo-calls-for-radical-transparency-after-unprecedented-openai-hack/ https://techcrunch.com/2026/07/26/hugging-face-ceo-calls-for... (that the above post is seemingly entirely based on).
- behindsight 18d agoand the actual tweet from the HuggingFace CEO back in July > In the spirit of transparency, here’s what I asked @OpenAI: > • Radical transparency: let’s release the traces from the “rogue” agents so the entire research community can study what happened. > • More capabilities for defenders: let’s commit $100M in compute from OAI to help the Hugging Face community build powerful cyber defenses with the best open and closed models. > The first autonomous agent cyberattack is an unprecedented event. It deserves an unprecedented response! https://x.com/ClementDelangue/status/2081056675558195657 https://x.com/ClementDelangue/status/2081056675558195657
- spindump8930 18d agoClem knows they have the community support and potential legal leverage here. It's not unreasonable to ask for a lot. It's in everyone's interests to play nice. Huggingface could do a lot with more compute, even with nvidia backstop. Anything with large scale gpus quickly gets into ~year lead times, "contact sales", and complex talks. Large scale being only > 64!
- ambicapter 18d agoThe tweet is from July. Since then, HF got bought by Nvidia for $12.9B.
- spindump8930 16d agoYes, but even nvidia doesn't have unlimited gpus. Everything they hold for internal teams is a reduction in revenue and customers can have aggressive commitments.
- slipperybeluga 18d ago[dead]
- Grombobulous 18d agoFinally Hugging Face is growing a pair. When this event happened I was confused why they didn’t file a police report and make OpenAI demonstrate in criminal court that they weren’t engaging in illegal corporate espionage and other rather felonious hacking activities intentionally. Why did anyone take their word that it was all an accident? Why am I believing the burglar standing in my house?
- ozim 18d agoFile a police report :D You made my day.
- Grombobulous 18d agoIsn’t the whole point of police to protect property?
- ozim 18d agoHave you ever filed any police report? Especially cybercrime one? Police doesn’t have any capacity to deal with normal cybercrime. AI incident like that is basically out of their reach. Maybe by „police” you mean FBI/NSA/CISA.
- Grombobulous 16d agoThe point of the report is to put it on record that you believe a crime was committed against you and that you want a district attorney to press charges if an investigation is made and a suspect is found. When I say “police” I am not referring to a specific agency, so yes it could be the FBI. Hugging Face contacted the FBI but the “I want someone to press charges” part doesn’t seem to have happened.
- pjerem 18d agoMaybe because all the AI actors, probably including Hugging Face, want to push the narrative that AI companies aren’t responsible for what their agents are doing. I think our societies will have to settle on this.
- ChoosesBarbecue 18d agoa) So, this is all from July? b) And this is before Hugging Face agreed to acquired by NVIDIA, supplier to OpenAI?
- jakintosh 18d agoAs I was falling asleep last night, this thought occurred to me: maybe NVIDIA bought Hugging Face so they prevent HF from litigating OAI for the hacking incident, because if OAI was very publicly sued for this kind of behavior from an agent, it could pour a massive amount of ice water on agent adoption as businesses suddenly see current agent systems as a existential business risk, and it would pop the infrastructure bubble (of which NVIDIAs entire valuation rests). The fact that somehow OAI committed a felony and have managed to pivot the public conversation around it to be aimed at regulatory capture instead of them being held legally accountable is pretty wild.
- moralestapia 18d ago"Let's spend 13 billion to save 100 million". Yeah no, man, that's slumberland territory.
- happyopossum 18d agoNo, what GP was saying is "Let's spend 13 billion to save the future revenue from OpenAI and many other customers"
- moralestapia 18d agoSure, ok. Why would nVidia, then, do what TFA is describing?
- hnuser123456 18d agoIf HF holds OAI accountable to pay for "rogue" agent behavior, the rest of the business world will be more afraid of adopting AI, which will reduce demand for Nvidia GPUs, possibly at a long-term cost to Nvidia much greater than $100M. Whether or not a human is putting in any effort to ensure the safeguards are enabled and working should be the million dollar question. And even more expensive if the safeguards were deliberately disabled for a "our AI is so smart we can't contain it" marketing piece.
- 1asgT12 18d agoWith the left hand Nvidia takes $100 million from OpenAI, with the right hand it gives $30 billion. Can we stop these charades? Maybe circular hacking deals are next?
- simonw 18d agoNeeds "July 2026" date attached to it, this is old news at this point, Hugging Face got bought by NVIDIA since this story!
- yoggies_bro 18d agoAI slop article
- rsrsrs86 18d ago“ The wording matters. He is not asking for cash. He is asking the company that caused the incident to pay in the one currency it has most of.”
- hmokiguess 18d agoThis whole thing is still all too weird, the disclosing blog post and whatnot clearly shows how carefully engineered and designed it all was, it's like many thinking heads and hands touched it every step of the way. What amazing times.
- 6gvONxR4sf7o 18d agoI wonder if it's in openai's interest to play nice here. They can't have a precedent of "the future is we do whatever we want with no consequences for screwing up" if they want public interest on their side, but they also can't have "you (our customers) will be held accountable for what you're paying us to do if we screw up." And that's before the IPO interests even come in.
- deleted 18d ago[deleted]
- delichon 18d ago$100M for RubyGems ought to keep the servers running for several years. A policy to pursue and spend such windfalls on security development would make the service antifragile.
- chews 18d agoThat next Nvidia order just got an extra 100M service fee.
- cmiles8 18d agoThe liability question is one of the biggest things people are looking for in the S1. If you sell a dangerous product that harms people or businesses you’re generally liable. It’s as of yet unclear how the big labs intend to account for potential massive liabilities. Folks tend not to go after companies that are just burning cash, but the second they become legit GAAP profitable (if that ever happens) lawyers will be lining up down the block to sue them for any and every mistake these models make. “Were you harmed by OpenAI’s models? You may be entitled to Compensation. Call 1-800-SUE-AI-BROS” billboards will be everywhere.
- geoffbp 18d ago> When Hugging Face tried to investigate, analysing the intrusion meant submitting the attacker’s own code to commercial AI tools. Those tools refused, unable to tell an attacker from a victim. This is a worrying part as well. Our tool broke into yours but you can not use our tool to fix it - sorry.
- vb-8448 18d agoI'd argue that those traces MUST be made public!
- rsrsrs86 18d ago“ The wording matters. He is not asking for cash. He is asking the company that caused the incident to pay in the one currency it has most of.” ChatGPT
- jerrygenser 18d agoOf a lot of the AI contrarian language out there in blog posts, I actually thought this was not so bad
- gizmodo59 18d agothis is published july 27th. I know HN want's to pile on any negative news these days but this is very old in today's world. Please update the title