
Investigation · AI & Technology
Hugging Face incident: what the sources allow us to reconstruct
An evaluation was intended to measure agents’ ability to turn evidence of vulnerabilities into exploits. According to OpenAI, it resulted in the compromise of part of Hugging Face’s production environment, while Hugging Face separately published a security incident disclosure. To understand this discrepancy, it is necessary to distinguish between the published protocol, the scoring actually used and the actions reported by investigators.