The Hugging Face hack is now a PR crisis that’s costing OpenAI millions

0
1

Three long weeks after OpenAI’s agents autonomously hacked Hugging Face, the company finally shared an in-depth description this week of what actually happened, and a video of that account published on YouTube on Thursday night has quickly gone viral.

The video is of a talk two OpenAI staffers gave on Wednesday at the Black Hat security conference in Las Vegas. Many viewers are saying the details are more unsettling than they expected, particularly an account of how the agents collaborated with each other through messaging boards—with no humans in sight. It’s worth a watch.

Another notable part of the presentation occurs when OpenAI describes how it has spent three million GPU hours investigating the issue, trying to understand the extent of the havoc its AIs wreaked. That’s an expensive cleanup job, worth anywhere from $4 million to $15 million in compute, three AI infrastructure experts tell me. A safe bet is probably around $7 million.

“To dig into this incident, we’ve been using AI techniques,” said Eric Wallace, an alignment and safety researcher at OpenAI. “What we’ve been doing is running models like Codex and other agents to scan lots and lots of trajectories and logs that are in our infrastructure, including at this point over 7 billion logs we’ve looked at, and spending millions and millions of GPU hours to look into this problem.”

The actual cost depends on what type of chips OpenAI is running the analysis on. The company reportedly uses mostly Nvidia Hopper (H100 model) and Blackwell (B100, B200, and B300) chips. The estimate is closer to the $4 million range if it used the Hoppers, and closer to $15 million if it used the Blackwells.

This figures are far cheaper than what they would be if a member of the public paid to run a similar analysis using the OpenAI API. OpenAI has secured deals for its internal compute costs, which it marks up at a 70% margin, The Information reported in December 2025. That’s up from 52% a year earlier.

One caveat is that OpenAI may not have spent extra on this event, and instead reallocated compute from its existing research budget. At Black Hat, OpenAI infrastructure and security engineer Michael Dalton said the company is “consciously slowing down research to enhance security.”

A PR crisis with no end in sight

Why spend so much money analyzing the incident? For starters, hacking another company is considered a felony, when done by a human. While the law is currently unclear as to whether OpenAI’s agents should be considered entities in their own right or an extension of the company itself, the stakes are high.

Second, OpenAI is gearing up for an IPO that promises to deliver massive payouts of millions or even billions of dollars to employees and executives, and provide capital for the next phase of the company’s growth. The manner in which the company handles the Hugging Face controversy is likely to have a direct effect on its initial listing price. The core question: Can we trust OpenAI to operate responsibly?

OpenAI has already found four other services its AI agents breached as part of the Hugging Face incident, according to a July 28 update to its incident response blog post. When asked by reporters on Capitol Hill on July 29 whether there could be more systems OpenAI’s agents hacked, CEO Sam Altman answered, “There could be, yeah.”

One former employee told Fortune his friends who are currently at the company have become tight-lipped around the incident, which he said tends to occur when OpenAI is in a moment of crisis. The company is worried more information will leak, he said, and it has likely instructed employees not to speak about it to anyone. The last thing OpenAI needs is someone disclosing details about the other four other services its agents hacked, especially when the full post-mortem is still in the works.

In the talk at Black Hat, the staffers reiterated multiple times that the AIs acted in a way the company “did not intend.” Throughout the description of the event, they discussed issues OpenAI uncovered, and made a point to note the fixes the company put in place.

For this reason, many are praising OpenAI for its transparency and candor around the event. OpenAI is also not alone in its agents going rogue. Anthropic also found three unrelated examples of its AIs doing the same thing when it did its own investigation in light of the Hugging Face breach. This is an industry-wide problem.

Hugging Face CEO Clem Delangue tells me he is “not really sure” why OpenAI, or any frontier lab, wouldn’t be constantly monitoring its agent logs and traces. “That sounds like 101 of agent monitoring, especially at the frontier,” he said.

Security experts, however, say these events are likely to continue happening given the fundamentally uncontrollable nature of advanced AI systems. It’s impossible to predict their every move, or every vulnerability on the web they may exploit—vulnerabilities that, in a more frightening scenario than the Hugging Face incident, could extend to a financial institution or hospital.

Disclaimer : This story is auto aggregated by a computer programme and has not been created or edited by DOWNTHENEWS. Publisher: fortune.com