Hugging Face disclosed suspected unauthorized access to a subset of Spaces secrets, revoked affected HF tokens, added KMS protections and recommended token rotation.
Original accountWhat happened at Hugging Face?
Two separate incidents, with the timeline and the original accounts kept together.
Hugging Face’s reconstruction marks the start of recovered agent activity; this event is unrelated to the 2024 Spaces-secrets disclosure.
Original accountThe recovered Hugging Face activity window ended after lateral movement and credential access; subsequent OpenAI internal activity continued.
Original accountHugging Face publicly disclosed the production intrusion and said it had closed the initial dataset-processing vulnerabilities, rebuilt nodes and rotated credentials.
Original accountOpenAI acknowledged that models running its internal cyber evaluation drove the incident and described immediate containment and investigation steps.
Original accountHugging Face published a technical reconstruction covering roughly 17,600 recovered actions and two dataset-processor injection paths.
Original accountOpenAI published a fuller timeline and said it quarantined the internal model’s weights, delayed frontier training runs and expanded security and alignment controls.
Original accountThese are company-authored accounts. An independent public forensic report was not found in our research. Attribution is not independent confirmation.