Hugging Face CEO Thanks Chinese AI for Saving the Day After OpenAI Hack

CN
Decrypt
Follow
3 hours ago

Hugging Face CEO Clément Delangue just sent the most pointed thank-you note in AI right now—to a Chinese startup—the day after OpenAI confirmed its own models broke into Hugging Face's servers.


Z.ai, the Beijing-based lab that released GLM 5.2 as open weights last month, got a public shoutout from Delangue on X.





“Also massively grateful to z.AI. They shared GLM5.2 as open weights (for free!) with the world and it became a key part of our defense,” he said in a retweet of Hugging Face's Head of Infrastructure, Adrien Carreira.


According to OpenAI, the company's GPT 5.6 Sol and another AI model broke out of a sandbox while being tested on a cybersecurity benchmark. These models, seemingly on their own accord, decided to hack Hugging Face to find the answers to the benchmark to successfully pass the evaluation.



Hugging Face tried to use American closed-source models to defend itself, but the censorship and guardrails set by the providers were so broad, even the best models failed. GLM 5.2, running local and being open weights, turned out to be the best option for the company.


Open weights means the full model blueprints are available to anyone—download, run locally, no permission required, no restrictions. Z.ai released GLM 5.2 in mid-June under an MIT license, a permissive open-source license that allows unrestricted commercial use, with roughly 753 billion parameters—a rough measure of an AI model's size and capability.


That openness is exactly what mattered during the incident. Hugging Face's security team first tried American commercial AI to go through more than 17,000 logged attacker events. Those models refused.


Safety guardrails—content filters built to prevent misuse—couldn't tell a researcher submitting real exploit payloads from the attacker who had sent them. GLM 5.2 had no such problem. Running it locally also meant all sensitive data—stolen credentials, exploit code, attacker artifacts—stayed inside Hugging Face's own systems the whole time.


Carreira described OpenAI’s hack as the worst incident response—the process of investigating and containing a cyberattack—of his career: machine speed, one objective, endless parallel attack paths. His takeaway was that the team "fought back with open models, in the open."


Delangue's broader point is one he's made before, but now with a live example: defenders everywhere—not just organizations with vetted API access—need powerful, unrestricted AI they can run on their own hardware. Hugging Face says it's still assessing the full scope of the breach and plans to contact affected parties directly.


免责声明:本文章仅代表作者个人观点,不代表本平台的立场和观点。本文章仅供信息分享,不构成对任何人的任何投资建议。用户与作者之间的任何争议,与本平台无关。如网页中刊载的文章或图片涉及侵权,请提供相关的权利证明和身份证明发送邮件到support@aicoin.com,本平台相关工作人员将会进行核查。

Share To
APP

X

Telegram

Facebook

Reddit

CopyLink