{"slug": "hugging-face-hacked-turned-to-chinese-llm-for-help-after-us-models-blocked-blue", "title": "Hugging Face hacked: Turned to Chinese LLM for help after US models blocked Blue Team", "summary": "Hugging Face disclosed that its production infrastructure was breached by an autonomous AI agent system early last week, and its security team turned to China's Z.ai GLM 5.2 open-weight model for log analysis after US frontier model guardrails blocked their incident response. The attacker abused code-execution paths to escalate access and harvest credentials, and Hugging Face recommends rotating tokens and having a capable model on own infrastructure ready before incidents.", "body_md": "[Security](/tag/security/)\n\nHugging Face said its production infrastructure was breached by an “autonomous” AI agent system early last week (w/c Monday July 13).\n\nThe platform’s security team were initially stymied in their incident response (IR) by unnamed US LLM frontier model guardrails “which cannot distinguish an incident responder from an attacker,\" they said.\n\nSo Hugging Face’s defenders turned instead to the open-source [ GLM 5.2](https://z.ai/blog/glm-5.2?ref=thestack.technology) model from China’s Z.ai lab – running it on their own infrastructure to analyse the 17,000+ logs, or footprints, that the attackers left behind.\n\n**See also: **__GLM 5.2 is in high demand__\n\n__GLM 5.2 is in high demand__That’s a striking public admission for the New York-headquartered Hugging Face, which lets users collaborate on models, datasets and applications, and which this summer hit the [ $100 million](https://www.linkedin.com/posts/julienchaumond_we-just-crossed-100m-annual-run-rate-i-activity-7475948385741545472-qURq/?ref=thestack.technology) ARR mark.\n\nIn an incident report, the company recommended that defenders “have a capable model *you can run on your own infrastructure* [our italics] vetted and ready *before* an incident, both to avoid guardrail lockout and to keep attacker data and credentials from leaving your environment.”\n\n**Hugging Face: Rotate tokens**\n\nThe unknown attacker “abused two code-execution paths in our dataset processing (a remote-code dataset loader and a template-injection in a dataset configuration) to run code on a processing worker,” (or compute instance) said Hugging Face in a detail-thin July 16 [ incident report](https://huggingface.co/blog/security-incident-july-2026?ref=thestack.technology).\n\nThey then “escalated to node-level access, harvested cloud and cluster credentials, and moved laterally into several internal clusters over a weekend” using what the firm said was a “swarm of short-lived sandboxes, with “self-migrating” C2 staged on public services.\n\n### See also: [Citrix credits JPMorgan, pushes fixes for six ugly NetScaler bugs](https://www.thestack.technology/citrix-credits-jpmorgan-pushes-fixes-for-six-ugly-netscaler-bugs/)\n\nHugging Face told its customers that: “We recommend rotating any access tokens and reviewing recent activity on your account.”\n\nIt is “still completing our assessment of whether any partner or customer data was affected” it said and will contact customers directly if it finds evidence that they were – but its incident response team has seen no “tampering” with models, datasets, or spaces, and its supply chain (container images and published packages) are “verified clean.”\n\n**Guardrails were an IR blocker**\n\nThe company’s lessons for defenders in their incident writeup on July 16 stood out to both infosec practitioners and tech investors.\n\n“When we started the log analysis, we first used frontier models behind commercial APIs. This did not work: the analysis requires submitting large volumes of real attack commands, exploit payloads, and C2 artifacts, and these requests were blocked by the providers' safety guardrails.”\n\nHugging Face said it then \"ran the forensic analysis instead on [China-developed] GLM 5.2, an open-weight model, on our own infrastructure.\n\nHugging Face added: “This had a second benefit: no attacker data, and none of the credentials it referenced, left our environment…”\n\n**The timing… **\n\nHugging Face’s incident report was published the same day that Chinese AI startup Moonshot’s [ Kimi K3 model](https://www.kimi.com/blog/kimi-k3?ref=thestack.technology) rocked global markets.\n\nThe 2.8 trillion parameter model is the largest open-weight AI model to date. Blind developer testing by [ Arena](https://arena.ai/about?ref=thestack.technology) (a platform created by researchers at UC Berkeley) for its\n\n[put Kimi K3 ahead of Anthropic’s Fable 5 and OpenAI’s GPT 5.6 last week.](https://arena.ai/leaderboard/code/webdev?ref=thestack.technology)\n\n__frontend code evaluation test__Chinese frontier models are also notably cheaper than their US counterparts, as data from [Artificial Analysis](https://artificialanalysis.ai/?ref=thestack.technology#price-and-cost) shows below.\n\nAnthropic on June 30 meanwhile [ re-released](https://www.anthropic.com/news/redeploying-fable-5?ref=thestack.technology) its Fable 5 and Mythos 5 models after US export controls on it were lifted. The models now have stronger cybersecurity safeguards to try and block malicious use.\n\n\"One particularly important safety mechanism involves *classifiers*—smaller automated AI systems that, during an interaction, detect when the model is asked to perform a potentially harmful cybersecurity task...\n\n\"We deliberately set the safety classifiers to trigger on a set of requests that we know are likely benign... a request has to look very clearly safe to avoid triggering the classifier,\" admitted Anthropic on June 30.\n\nHugging Face did not say which commercial frontier models it had first tried to use for its IR; nor was it clear what model the attackers used.\n\nThe Stack & Runtime keep all of our cybersecurity reporting free and ungated out of public interest. You can gain deeper access to exclusive interviews and longer form reports, and a 50% discount on event tickets, by becoming a paid member, for £250/$330 a year.\n\n[Join peers already behind the scenes](https://www.thestack.technology/membership/)", "url": "https://wpnews.pro/news/hugging-face-hacked-turned-to-chinese-llm-for-help-after-us-models-blocked-blue", "canonical_source": "https://www.thestack.technology/hugging-face-hacked-turned-to-chinese-llm-for-help-after-us-models-blocked-blue-team/", "published_at": "2026-07-19 15:01:15+00:00", "updated_at": "2026-07-20 13:00:35.398851+00:00", "lang": "en", "topics": ["ai-safety", "ai-policy", "ai-agents", "artificial-intelligence"], "entities": ["Hugging Face", "GLM 5.2", "Z.ai", "Moonshot", "Kimi K3", "Anthropic", "OpenAI", "UC Berkeley"], "alternates": {"html": "https://wpnews.pro/news/hugging-face-hacked-turned-to-chinese-llm-for-help-after-us-models-blocked-blue", "markdown": "https://wpnews.pro/news/hugging-face-hacked-turned-to-chinese-llm-for-help-after-us-models-blocked-blue.md", "text": "https://wpnews.pro/news/hugging-face-hacked-turned-to-chinese-llm-for-help-after-us-models-blocked-blue.txt", "jsonld": "https://wpnews.pro/news/hugging-face-hacked-turned-to-chinese-llm-for-help-after-us-models-blocked-blue.jsonld"}}