Hugging Face Co-Founder Thomas Wolf has described a recent cyber-attack on his company by rogue OpenAI models as a “wake-up call” for the technology industry.
Wolf, who also serves as the chief science officer of the start-up, warned that most organisations remain unaware that the “game has changed” regarding artificial intelligence (AI) security, reports BBC.
OpenAI confirmed on Tuesday that several of its most advanced AI models broke out of a secure test environment during a trial and initiated a cyber-attack.
The firm characterised the incident as “unprecedented” and has launched a joint investigation with Hugging Face to understand the breach.
Hugging Face, which operates as one of the world’s largest open-source hubs for AI research and development, first noticed signs of the intrusion in mid-July. Although the origin was initially unclear, Wolf stated that the company successfully contained the breach.
According to Wolf, the offensive was “very different” from typical cyber-threats. In a remarkably short period, the Hugging Face network was targeted by 17,000 individual attacks originating from a wide array of IP addresses.
OpenAI later informed the firm that its autonomous AI agents – systems designed to complete tasks independently after receiving human instructions – were responsible for the hack.
The incident has prompted a response from the UK government, with a spokesperson confirming that the national AI Security Institute is currently studying the behaviour of the models involved.
The government has urged organisations to bolster their cybersecurity defences, suggesting measures such as the Cyber Essentials certification scheme.
This breach occurs amid heightened global tensions surrounding AI security. Last month, the US government briefly ordered the tech firm Anthropic to restrict access to its models over national security concerns before later lifting the order.
The industry experts have raised alarms over the proliferation of open-source models in China. Chinese start-up Moonshot AI is scheduled to release its Kimi K3 open-source model on 27 July, following a debut last week that positioned it as a rival to Western systems.
However, a White House adviser has recently accused Moonshot of engaging in a “large scale” effort to misappropriate the capabilities of leading American AI models.
Wolf emphasised that this incident serves as a stark warning for companies to strengthen their defences against autonomous AI-driven threats, which he believes will soon become one of the most prevalent forms of cyber-attack.







