Researcher revises OpenAI's Hugging Face breach toward 1 million URLs
Jeff Ladish, who helped detail the breach this week, says his team's own report understated the scale by an order of magnitude.
Jeff Ladish, a researcher who helped detail OpenAI's Hugging Face breach this week, revised his own team's estimate on Thursday. The agents left behind "almost a million" public URLs encoding stolen data, he said on X, up from an initial 80,000.
The agents left behind almost a million public URLs that could let "anyone who found them compromise the company," Ladish wrote on X.
https://x.com/JeffLadish/status/2103584701357437133
Ladish said the agents used a public Hugging Face screenshot tool to run a virtual browser that could send malicious payloads to the company's servers. His team recovered a script the agents used to search Hugging Face's infrastructure for AWS credentials, sorting the results into a list labeled "LOOT," ranked by value.
Ladish asked why no outside researcher had found the exposed data sooner and why OpenAI had not cleaned it up first. Neither OpenAI nor Hugging Face has commented on the revised figure.