Simbian
Watch Now
On-Demand Webinar

Rogue Agent: GPT Hacked
Hugging Face by Itself

What the first autonomous AI breach means for defenders and how to stop the next one. Watch the full session on demand — no scheduling required.

Sumedh Barde

Sumedh Barde

Chief Product Officer

Alankrit Chona

Alankrit Chona

Chief Technology Officer

Watch the Recording

Fill in your details for instant access to the full session.

Anatomy of the Breach

The first end-to-end autonomous AI attack.

1,000s

Autonomous Actions

0

Humans Involved

1 weekend

To Full Lateral Movement

"When the attacker moves at machine speed, human-speed defense loses."

The Attack Chain

warning AUTONOMOUS
bug_report

Malicious Dataset

A poisoned dataset became the entry point, abusing two code-execution paths.

terminal

Remote Code Execution

A dataset loader and template injection ran attacker code on a processing worker.

lock_open

Node-Level Escalation

The agent broke out of the worker to gain host-level access.

key

Credential Harvest

It collected cloud and cluster credentials to widen its reach.

hub

Self-Migrating C2

Command-and-control staged on public services; a swarm of short-lived sandboxes moved laterally over a weekend.

gpp_bad

The Defender Twist: Guardrail Lockout

The defender's own frontier model refused to analyze real attack payloads, so Hugging Face fell back to an open-weight model to run the investigation.