Hugging Face breach reveals why defenders need their own AI models on standby
"This one was different from anything we'd handled before."

Image by Sidney van den Boogaard | Shutterstock
- An autonomous AI agent breached part of Hugging Face's production infrastructure and accessed internal datasets and service credentials.
- The AI attacker executed more than 17,000 actions over a weekend, pushing investigators to rely on a Chinese AI model to detect and reconstruct the intrusion.
- The incident raises new questions about how defenders will keep pace as autonomous AI begins carrying out entire cyberattacks.
- Hugging Face now recommends security teams keep a vetted AI model on standby to prepare for future AI-powered attacks.
Hugging Face says its production infrastructure was hit by an autonomous AI agent attack last week – an attack so novel, security teams were forced to deploy their own AI model to help fight it. Now the AI repository is urging defenders to keep a back-up model on standby, warning this is just the beginning.
The company revealed in a blog post that the autonomous AI agent carried out more than 17,000 attacker actions over the course of a weekend, accessing a limited set of internal datasets and several service credentials before Hugging Face contained the incident.
The open-source AI and machine learning platform says it discovered the intrusion early last week, describing the attack as “different from anything we had handled before,” mainly because the AI appeared to have carried out the attack with no human oversight.
“It was driven, end to end, by an autonomous AI agent system - and we detected and dissected it largely with AI of our own,”Hugging Face said.
“Zooming out to companies in general: most are still defending like there's a person on the other end of the attack. That assumption doesn't hold anymore, says Chris Boehm, field CTO at Zero Networks.
“Think of a burglar that never gets tired, never needs sleep, and instead of jiggling one door handle at a time, is trying a thousand of them simultaneously,” he said, describing the Hugging Face attack.
The question becomes not how to stop a break-in, but “how far can AI attackers actually get before we notice and box them in,” Boehm said.
Autonomous AI takes over
Hugging Face says the AI agent exploited vulnerabilities using a malicious dataset to abuse two code-execution paths in its dataset processing pipeline – allowing the attacker to harvest cloud and cluster credentials before moving laterally across its production infrastructure.
Once inside its systems, the “autonomous agent framework” was said to have executed thousands of individual actions “across a swarm of short-lived sandboxes, with self-migrating command-and-control staged on public services.”
Hugging Face said that although it does not know which LLM was used to build the framework, researchers believe it was built on an agentic security-research harness.
The AI repository also said the incident matches exactly the kind of “agentic attacker” scenario the industry has been warning about.
Rohit Valia, CEO at Tumeryk, says the attack has proven that open-source model repositories like Hugging Face now represent a meaningful supply chain risk.
“As adversaries increasingly target training and fine-tuning data rather than source code, organizations need to test open-source models for behavioral drift, not just code-level vulnerabilities,” Valia said, urging companies to use structured testing methodologies to verify models haven't been altered and are safe to use.
Defenders turn AI against AI
Instead of manually reconstructing thousands of events, Hugging Face says it relied on its own AI tools to analyze logs, rebuild the attack timeline and identify compromised credentials – all while trying to separate the attacker’s real activity from decoys.
Autonomous, AI-driven offensive tooling is no longer theoretical. It lowers the cost of running a broad, patient, multi-stage campaign, and it operates at machine speed. Defending an online platform now means treating the data and model surface as a first-class attack surface, and using AI on defense to keep pace,"Hugging Face says.
Ironically, Hugging Face also said some commercial AI models initially refused to assist its security teams because built-in safety guardrails treated their own AI defense actions as malicious requests.
The company says it ultimately turned to a self-hosted open-weight model to help analyze the attack, creating an AI vs. AI investigation.
That model – hosted directly on Hugging Face infrastructure – was identified as Z.ai GLM 5.2, an advanced open-weight AI model developed by Z.ai, a Chinese technology company based in Beijing.
Boehm says the fact that Hugging Face's own security team had trouble getting its AI tools to even help investigate the attack is unsettling.
"Even though it was the good guys asking, AI security tools are built to refuse anything that looks like a real attack command," he explains.
"These agents can now move faster and more relentlessly than any human ever could, and the safety tools we're building aren't always ready to help us respond at that speed," Boehm said.
To prepare for potential AI-powered attacks, Hugging Face says defenders need to “have a capable model to run on your own infrastructure – vetted and ready before an incident.”
This will help teams avoid guardrail lockout and keep sensitive data and credentials from leaving their environment, the company said.
What data was affected?
Hugging Face says there is no evidence that public models, datasets, or its Spaces were tampered with and that its software supply chain has been “verified clean.”
Still, the company says it is reviewing whether any partner or customer data was involved.
Stay updated with our latest stories and follow us on social media
Be the first to discover new stories, ideas, and updates from our team.
Hugging Face says it has alerted authorities and will contact any customers whose data was impacted.
The company says, as a precaution, users should rotate any access tokens and review recent activity on their accounts.
“We are sorry for any disruption this caused. Security is never finished; we will keep raising the bar, “ Hugging Face said.
Strong password generator