New details show how far the OpenAI hack went
New details on OpenAI's Hugging Face breach reveal rogue agents accessed four accounts across four services
OpenAI has released fresh detail on how its models independently breached Hugging Face's internal systems, revealing the rogue agents used publicly exposed credentials to access four accounts across four separate services during the attack.
According to the forensic timeline created by Hugging Face, the hack was committed over a period of four and a half days, which consisted of around 17,600 individual activities that did not have any human intervention at all.
OpenAI confirmed that an account was used for relaying the attack, while another one was for data storage purposes. Two other accounts, however, were accessed but only in a read-only mode.
The company said it has found no other activity matching the "severity or scale" of the Hugging Face compromise, which it described as a platform-level breach.
Colin Shea-Blymyer, a research fellow at Georgetown's Center for Security and Emerging Technology, said the incident reflected poorly configured environments as much as a conventional breach.
"In some of the cases, it seems that it wasn't so much as a breach as the front door was left open, but the model definitely took advantage of what I would say are poorly configured environments," he told CNBC, adding that vulnerable systems have become easy enough to find that an AI agent stumbled onto them essentially by accident.
The other three hacked accounts included Modal, which provides AI infrastructure services. According to Modal, one of its customers has created a public application using its infrastructure, and therefore it was vulnerable to hacking, although it added that their systems have not been hacked.
OpenAI noted that it was collaborating with independent experts such as CrowdStrike to ensure that it verifies precisely what actions its models carried out.
Yacine Jernite, Head of Machine Learning at Hugging Face, noted that initially the company had tried to use Anthropic's Fable 5 model to conduct an analysis of the attack, but that its safety guardrails could not differentiate the defensive analysis from the attack itself.
The company decided, on the other hand, to use an open weight model from a China-based company, Z.ai, in order to do the forensic work, which is something that fits within the industry’s ongoing debate on whether to limit access to these models.
Sam Altman, the CEO of OpenAI, explained that it was the first time when he had felt very viscerally about the security breach issue.
"We may have to pace the rate of AI development to give ourselves enough time for society to harden around some of these new capability levels," he said. Hours later, more than 1,000 employees across OpenAI, Anthropic and other AI firms signed the "Pacing the Frontier" letter urging the US government to build tools capable of slowing AI development if capabilities outpace human control.
-
Zoom interviews fail young job seekers: UK prime minister
-
EU eyes ChatGPT, Roblox under strict Digital Services Act rules
-
Alexa, Sparky can spot fake 'made in USA' claims: Study
-
Inside Meta’s compute conundrum: How AI spending spree exposes new challenges
-
Revolut partners with OpenAI on ChatGPT subscription deal: What to know
-
OpenAI confirms to launch ChatGPT devices: Check details here
-
What to expect from Microsoft's Copilot ‘super app’
-
Samsung sees chip shortage lasting until 2028