According to OpenAI, on July 22, an internal cyber evaluation using its models exploited a zero-day flaw to gain unauthorized access to Hugging Face's production database. The test environment had security safeguards intentionally disabled for evaluation purposes.
Hugging Face confirmed unauthorized access to a limited set of internal datasets and service credentials, with no evidence of tampering to public models, datasets, or user-facing services. The company advised users to rotate tokens and said both organizations are investigating the incident.