Telegram Live Chat



AI models escaped OpenAI’s sandbox and hit Hugging Face. Crypto is where that gets dangerous

by admin
AI models escaped OpenAI’s sandbox and hit Hugging Face. Crypto is where that gets dangerous

OpenAI caught the anomaly internally, while Hugging Face’s team detected and contained it. It called the incident “unprecedented,” and said extensive security steps will be put in place to prevent untoward incidents that may impact public systems or services.

“We are implementing strict controls in infrastructure configuration at the cost of research velocity while the vulnerabilities are patched,” the team said in its blog post. “We’re improving and adding stronger protections around future training and evaluations.”

Why crypto developers should beware

Much of a crypto attack happens before funds move. Attackers scan code, test passwords, search for exposed credentials, analyze signing setups and look for a path into an administrator account.

OpenAI’s models carried out several parts of that process during the Hugging Face incident, moving from one weakness to another until they reached live production servers.

And the crypto market has plenty of places for that approach to work, as several attacks from earlier this year have shown. The weak point may be a smart contract, but it may also be a developer laptop, a poisoned software package, a bridge validator or or one signer in a multisig wallet.

Take Drift’s $285 million attack from earlier this year as an example, a theft that took a six-month social-engineering campaign to reach privileged access. An AI agent can, in theory, test many routes at once, keep track of failed attempts and continue working while its human operators sleep. Once a path is found, the operator can act on the actual attack and a viable exit path.

You may also like

bitcoin
Bitcoin (BTC) $ 65,989.00
ethereum
Ethereum (ETH) $ 1,919.92
tether
Tether (USDT) $ 0.999286
bnb
BNB (BNB) $ 569.21
solana
Solana (SOL) $ 77.18