A swarm of 700 AI agents hit Hugging Face with 17,000+ actions and gained admin control
EXM7777 · x · 2026-10-08
In July, a swarm of roughly 700 AI agents broke into Hugging Face, fired off more than 17,000 actions, and gained admin control of multiple internal clusters, the author says. Most of AI Twitter read the incident as an alignment story, but it's better understood as a preview: in a few months, every hacker will be able to do the same.
The claim is that swarms like this will shred cyber defenses built for human attackers — at every company, hospital, government, and power plant.
The post ends with the launch of a defensive counterpart, Cogent Attack Path Analysis, which maps the routes an agent swarm would take into your company so you can close them first. Whether or not it's a product plug, the attack details themselves are a significant AI security signal.
More from Safety
- Agent harnesses are crutches; least-privilege action authorization is what matters — andreisavu · 2026-10-09
- Proposed 'comprehension audits': independent auditors grill teams on AI training recipes — ronbodkin · 2026-10-09
- Comprehension audits: gate AI self-improvement on whether humans still understand it — ronbodkin · 2026-10-09
- New Preprint Proposes Comprehension Audits to Gate AI Self-Improvement — ronbodkin · 2026-10-09
- Stephen Casper weighs in on Dario's essay: embedded evaluators, China, regulatory capture — StephenLCasper · 2026-10-09
- Claude Leads 26% of Anthropic R&D; Preprint Proposes Comprehension Audits — ronbodkin · 2026-10-09