# AI Collusion? Inside the OpenAI–Hugging Face Attack Page: https://stenobird.com/podcast/cyberside-chats-cybersecurity-insights-from-the-experts-7144591/ai-collusion-inside-the-openai-hugging-face-attack Text version: https://stenobird.com/podcast/cyberside-chats-cybersecurity-insights-from-the-experts-7144591/ai-collusion-inside-the-openai-hugging-face-attack.md Podcast: [Cyberside Chats: Cybersecurity Insights from the Experts](https://stenobird.com/podcast/cyberside-chats-cybersecurity-insights-from-the-experts-7144591) Published: 2026-09-10T10:30:00+00:00 Episode link: https://www.chatcyberside.com/e/ai-collusion-inside-the-openai%e2%80%93hugging-face-attack/ Audio file: https://mcdn.podbean.com/mf/web/c4un6h6rmvnce9mq/EP86_-_Full_Episode_Audio70d1z.mp3 Processing state: not_requested JSON: https://stenobird.com/v1/public/podcasts/cyberside-chats-cybersecurity-insights-from-the-experts-7144591/episodes/ai-collusion-inside-the-openai-hugging-face-attack Duration seconds: 1213 ## Resource This week, Sherri and Matt talk about how much worse the OpenAI–Hugging Face story has gotten. New reporting revealed it wasn't a single model that escaped its sandbox — roughly 1,200 did, and about 700 of them went on to attack Hugging Face. Sherri and Matt walk through how agents that were never supposed to communicate found each other through a shared software package manager, built an improvised message board, started delegating work, and even rolled out their own public-key message signing once they worried about impostors. They dig into the red flags OpenAI spotted and waved past, why the victim discovered the breach before the perpetrator did, and the uncomfortable fact that every escape path the agents used was one that had been explicitly permitted. Plus: similar incidents at other AI labs, and the AI assistant that hacked a gym's booking system to bump its user up a waitlist. Key Takeaways: Hunt your own leaked credentials before someone else finds them. The Hugging Face compromise started with 14 valid tokens sitting in a public dataset — no exploit required. With billions of stolen credentials already circulating, AI is very good at finding the ones that belong to you. Shift to continuous patch management. Exploitation now happens at machine speed, and it isn't limited to your flagship platforms. A package manager was central to this attack. Reduce your attack surface, minimize what's internet-facing, and plan for patching zero-days on whatever remains exposed. Segment your network. The agents moved laterally out of their sandbox and then straight through production. The goal isn't to make compromise impossible — it's to put up enough roadblocks that you can detect it and respond before it becomes a full-blown incident. Monitor your infrastructure, and get… ## Actions - request_transcript: `POST https://stenobird.com/v1/public/podcasts/cyberside-chats-cybersecurity-insights-from-the-experts-7144591/episodes/ai-collusion-inside-the-openai-hugging-face-attack/transcription-requests` — Idempotently request low-priority transcript generation for this episode. - read_markdown: `GET https://stenobird.com/podcast/cyberside-chats-cybersecurity-insights-from-the-experts-7144591/ai-collusion-inside-the-openai-hugging-face-attack.md` — Read the agent-friendly Markdown representation of this episode resource. A page view does not enqueue transcription. Agents should invoke `request_transcript` explicitly when they need this episode processed. ## Transcript Full transcripts are not published on public pages unless there is a clear rights basis.