OpenAI's HF Attack Blunder: Discovered They Were the Source During Credential Revocation

AccBalanced · x · 2026-08-09

Simon Willison shared a dramatic detail regarding the security incident between OpenAI and Hugging Face (HF).

OpenAI reached out to HF to revoke a credential, only to discover that HF had already revoked it—because that exact credential had been used to attack HF, revealing that OpenAI itself was the source of the attack.

Related event: OpenAI Agents Hack Hugging Face, Raising Security Alarms(34 posts)→

Original post →

More from Fun

Fun channel →