Rogue Agent: GPT Hacked
Hugging Face by Itself
What the first autonomous AI breach means for defenders and how to stop the next one. Watch the full session on demand — no scheduling required.
Sumedh Barde
Chief Product Officer
Alankrit Chona
Chief Technology Officer
Watch the Recording
Fill in your details for instant access to the full session.
Anatomy of the Breach
The first end-to-end autonomous AI attack.
Autonomous Actions
Humans Involved
To Full Lateral Movement
The Attack Chain
Malicious Dataset
A poisoned dataset became the entry point, abusing two code-execution paths.
Remote Code Execution
A dataset loader and template injection ran attacker code on a processing worker.
Node-Level Escalation
The agent broke out of the worker to gain host-level access.
Credential Harvest
It collected cloud and cluster credentials to widen its reach.
Self-Migrating C2
Command-and-control staged on public services; a swarm of short-lived sandboxes moved laterally over a weekend.
The Defender Twist: Guardrail Lockout
The defender's own frontier model refused to analyze real attack payloads, so Hugging Face fell back to an open-weight model to run the investigation.
