Hugging Face Hit by AI Attack, Uses Open-Source Models for Forensics

xiaohu · x · 2026-07-20

Hugging Face recently experienced an AI-involved attack. The investigation lasted an entire weekend, generating over 17,000 action logs.

They initially used commercial closed-source models for forensic analysis. However, because they needed to submit a large volume of real attack commands, exploit payloads, and C2 traces, they were blocked by safety guardrails and couldn't proceed. Ultimately, they switched to the open-weights model GLM 5.2 hosted in their own environment to analyze the logs. This bypassed guardrail restrictions and avoided exposing attack data and related credentials outside their infrastructure.

Related event: HF Hit by AI Agent Attack, Open-Source Model Used After API Guardrails Block Forensics(25 posts)→

Original post →

More from Infra

Infra channel →