
Autonomous AI Agent Breach Exposes Hugging Face Credentials
Hugging Face disclosed that attackers used an autonomous AI agent to breach its production infrastructure, stealing internal datasets and cloud credentials after exploiting a malicious dataset to trigger two code-execution vulnerabilities; the company evicted the attacker, rebuilt affected nodes, rotated credentials, and deployed enhanced detection while informing law enforcement and engaging external forensics. There is no current evidence of tampering with public models or Spaces, though the incident highlights evolving AI-driven attack risks. Users are advised to rotate access tokens and review account activity; Hugging Face also stresses having a vetted self-hosted model ready to use during incidents to avoid guardrail lockout and contain attacker data.
