Hugging Face, an platform that hosts AI models and datasets, disclosed that its internal data repositories and service credentials were compromised in a breach disclosed last week. While the company made the announcement on Friday, it continues to investigate whether any customer or partner information was exfiltrated.
According to a blog post, a dataset uploaded to the service exploited a security flaw to execute malicious code on Hugging Face’s servers, enabling the attackers to elevate privileges and expand access to internal systems.
The firm announced that it has revoked and rotated the compromised credentials. It also urged users to replace any API keys held on the platform and to scrutinize account activity for anomalies.
Hugging Face confirmed that it has patched the exploited vulnerability. The episode highlights the broader difficulty of preventing attackers from leveraging platforms and tools to infiltrate internal data stores, even when traditional attack vectors such as stolen credentials or perimeter weaknesses are addressed.
Hugging Face attributed the intrusion to an external AI agent that performed “tens of thousands of individual actions across a swarm of short‑lived sandboxes, with self‑propagating command‑and‑control staged on public services.”
The company did not promptly furnish evidence to support this assertion when approached by TechCrunch.
Hugging Face reported that its internal anomaly‑detection system identified the intrusion and employed an in‑house large language model to examine server logs documenting the attack.
Initially, the firm attempted to use a frontier AI model from a third‑party provider — without disclosing the vendor — but discovered that the provider’s guardrails blocked the analysis. Consequently, Hugging Face switched to a proprietary large language model, avoiding the need to transmit sensitive attack logs to an external AI service.
Security researchers have long noted that certain frontier models, such as Anthropic’s Mythos and Fable, impose strict constraints that limit defenders’ ability to query them for cybersecurity‑related inquiries, including defensive and investigative work.
Frontier AI developers, including Anthropic, have clashed with the U.S. administration over concerns that such models could be weaponized for offensive cyber operations. Following export‑control measures, Anthropic withdrew Fable from public availability.
Hugging Face disclosed that it has reported the incident to law‑enforcement agencies and engaged forensic cybersecurity specialists to investigate the breach and assess its security posture.
It remains unclear whether Hugging Face conducted a comprehensive security audit prior to the incident. A company spokesperson did not respond to a request for comment on Monday.

