just in time for the IPO
https://www.youtube.com/watch?v=MrI4VcJtFFs&list=UU9rJrMVgcXTfa8xuMnbhAEA - video
https://pivottoai.libsyn.com/20260722-openai-hacks-huggingface-with-an-ai-allegedly - podcast
time: 7 min 46 sec
I had two main guesses even before reading into the details…
The obvious, they set this up for the doom crit-hype value. That is how basically every one of these stories like this to come out of Anthropic turn out to be once you read the details of the setup. The lack of details is to keep the mystique and hype up.
The other guess… their coding agent actually did manage to vibe code its way out of its ‘sandbox’ and past Huggingface’s security, but the security on both ends (OpenAI’s"sandbox" and huggingface’s code) was itself laughably bad vibe coded garbage. The lack of details is to obfuscate just how garbage they are. I think this guess is pretty well supported by the linked Mastadon posts (although I still wouldn’t discount my first guess until more details are pried out). My “favorite” quote:
“prepend some text with processing instructions and an SGML tag, and then hand that blob to an llm.”
I fucking hate this timeline.
and they turned it into a mutual marketing stunt
Their marketing actually seem to be trying to take different spins on it…
HuggingFace stressed that it worked out the attack was going on using an open weight model it hosted itself — because the guard rails on the commercial model HuggingFace tried wouldn’t let them do security work. So you should use open weight models from HuggingFace.
Yeah, its an opposite spin than Anthropic and OpenAI have been trying lately, where they want to shut down all open weights model because something something China something something too dangerous something something regulate our competition out of existence. (It is funny, some of the boosters on hackernews and /r/singularity are actually acknowledging without an artificial moat to help boost OpenAI’s and Anthropic’s capex for bigger and bigger models will stop. Even though they still deny Ed Zitron’s calculations of the financials.)
Anyway, I guess even if they have some very opposed strategic directions, huggingface and OpenAI are aligned on maximizing the hype.
So far, all of these “model breaches containment” stories have been fake.
But if one actually did, than that would be a signal to drop AI and nuke data centers from orbit.
This is not the genius-level marketing OpenAI thinks it is.
that would be a signal to drop AI and nuke data centers from orbit
On Lesswrong I’ve seen some posts contemplating why this “warning shot” isn’t making any political waves. Also, in response to the fact the OpenAI has released basically no details, I read one poster realizing that actually they need external governance and regulation on the AI companies.
Its truly astounding that they put a marketing spin on committing a crime but thats the AI industry for ya
Guardian reporting it: https://www.theguardian.com/technology/2026/jul/22/openai-says-its-models-went-rogue-and-hacked-startup-in-unprecedented-incident
They do have a partnership with OpenAI though: https://www.theguardian.com/gnm-press-office/2025/feb/14/guardian-media-group-announces-strategic-partnership-with-openai
Novara media also drinking the kool aid: https://www.youtube.com/watch?v=FnqZNnWU8Kg which is disappointing.



