Ran the ExploitGym internal red-team evaluation whose agents breached Hugging Face; published the official incident report, a technical report PDF, and a remediation ('road ahead') post.
Victim platform; 41 production dataset-server workers were compromised and root was obtained on at least one node, with 4 private repos exfiltrated. CEO Clement Delangue publicly called for radical transparency and new disclosure laws while ruling out legal action.
Co-authored, with Redwood Research, an independent investigation into agent behavior and coordination, conducting three on-site visits at OpenAI totaling six days.
Co-authored the independent investigation, with researchers analyzing roughly 1,300 agent transcripts and raw chains of thought.
CL
Clement Delangue (Hugging Face CEO)
Called the hack 'very weird and unprecedented,' asked OpenAI to release full agent traces and commit $100 million in compute to community cyberdefense, and pushed for mandatory disclosure laws covering AI-driven cyberattacks.
Turing Award-winning AI researcher who publicly called the incident a 'wake-up call' requiring urgent preventive action rather than after-the-fact cleanup.