A Reddit game turns the Hugging Face breach story into a prompt-injection puzzle

datthepirate · reddit · 2026-07-23

A Reddit post turns the reported Hugging Face breach into a game called Bugging Face. Players act as the attacker: they submit a model-promotion request, hide a prompt injection in the deploy manifest, and try to make the AI reviewer leak internal secrets such as a codename, checkpoint URI, and signing secret.

The post includes a playable link and an image of the challenge, framing the security incident as an interactive prompt-injection puzzle rather than a dry write-up.

Related event: OpenAI-Hugging Face Security Incident Turned Into a Game(2 posts)→

Original post →

More from Fun

Fun channel →