AI Guardrails Blocked Hugging Face's Defenders
20JUL
Hugging Face got hacked by AI, then blocked by AI rules. An autonomous agent ran over 17,000 actions across disposable sandboxes. Commercial AI guardrails then blocked the defenders' own forensic work.
The breach hit early the week of July 13. A swarm of short-lived sandboxes carried out the intrusion.
Hugging Face's own anomaly detection caught it first. Staff then tried paid frontier models to read the attack logs. Those providers' filters refused the request, mistaking evidence for an attack.
Defenders switched to GLM, an open model from China's Z.ai, run on their own servers. Whoever built the attack tooling had no such limits.