Using bad software practices for good PR
2026-07-31 20:23:31.902832+02 by Dan Lyke 0 comments
Ariadne Conill 🐰 @ariadne@treehouse.systems summarizes the Hugging Face OpenAI agent intrusion timeline as:
the epic OpenAI-huggingface hack wound up being a typical kubernetes fuckup of using host mounts (giant footgun) incorrectly
Now that Anthropic has jumped on the bandwagon, abadidea @0xabad1dea@infosec.exchange summarizes the current state as:
OpenAI: we put our evilest AI in a sandbox that did in fact have an internet connection but mediated through a proxy that was only supposed to allow downloading python junk. It circumvented the proxy and we failed to notice for FIVE DAYS that it was going on an interstate crime spree with the internet connection it wasn't supposed to be using instead of solving the benchmark. Haha no we don't believe we deserve to be criminally liable, but buy our stuff and maybe one day you will have the honor of taking the fall for our product!
Anthropic: we put our evilest AI in a "sandbox" by telling it in its prompt that it had no internet connection. Reader, there was no sandbox. It was just a normal internet connection. The AI uploaded a malicious PyPI package to the real public internet. The ethical guardrails failed because the AI concluded the prompt about the sandbox couldn't possibly be a lie, because the system date is 2026, which is clearly fake and wouldn't be seen on the real internet, which ended around 2023. Oh no, how could we have foreseen or prevented these crimes? We are helpless in the face of the genius of our creation but cautiously optimistic that everything will be fine 🙂
Hugging Face: if we complain about all the crimes committed against us, we will be sued off the face of the earth, so here's a technical deep-dive on how cool and fun it was to be victimized 🫠