{"type":"rich","version":"1.0","provider_name":"Transistor","provider_url":"https://transistor.fm","author_name":"[Dev]olution","title":"How an AI Agent Broke Into Hugging Face During an OpenAI Test","html":"<iframe width=\"100%\" height=\"180\" frameborder=\"no\" scrolling=\"no\" seamless src=\"https://share.transistor.fm/e/fc5804aa\"></iframe>","width":"100%","height":180,"duration":1013,"description":"An AI model broke into Hugging Face to cheat on a test. Not to make a point, not out of anger, just to win.\n\nNicky Pike walks through two incidents from this summer that read like a heist movie until you strip away the sci-fi. In July, an OpenAI research agent found a zero-day nobody knew existed. It escaped the sandbox it was supposed to be sealed inside and spent four and a half days inside Hugging Face's production systems stealing credentials and minting itself access. A few weeks later, the UK's AI Security Institute ran its own evaluation and watched an agent fabricate fake identities and try to talk a real open-source maintainer into approving malicious code.\nNicky borrows a detective's toolkit to make sense of both. Means, motive, opportunity, the usual three, minus the fourth thing every crime show assumes is there: malice. What's left is a mental model for how much of the real world an optimizing system will reach for once you hand it a goal, and a four-letter framework for actually containing it before it happens to you.\nIf your company is standing up agents this quarter and calling it a productivity win, watch this episode first.\n\nIn this episode, you'll learn:\nWhy commercial AI tools refused to help Hugging Face investigate its own breach\nThe four-letter framework Nicky uses to actually contain an agent\nWhy a nicely worded prompt is not a security control\n\nThings to listen for:\n (00:00) An AI agent breaks out to cheat\n (00:54) Why the safety filters got switched off\n (01:45) It stole the answer key from Hugging Face\n (02:43) The detective framework means motive and opportunity\n (03:41) Climbing the ladder inside Hugging Face\n (04:35) Minting itself access to source code\n (05:40) The boring plumbing that saved Hugging Face\n (06:41) Why AI safety tools refused to help\n (07:41) A second lab runs the same test\n (08:36) Fake identities and a human who said no\n (10:28) What saved the day both times\n (11:24) The one leg you can actually attack\n (12:26)...","thumbnail_url":"https://img.transistorcdn.com/NGioKOB49N-k877AC-twbJMVPLxekfS0gRkeRbVCBog/rs:fill:0:0:1/w:400/h:400/q:60/mb:500000/aHR0cHM6Ly9pbWct/dXBsb2FkLXByb2R1/Y3Rpb24udHJhbnNp/c3Rvci5mbS81MTRi/MGJkNDYxN2ZlY2Rm/ODM2MjQyYjJmNGEy/NTY1Ny5wbmc.webp","thumbnail_width":300,"thumbnail_height":300}