Rendered at 14:41:55 GMT+0000 (Coordinated Universal Time) with Cloudflare Workers.
jakintosh 19 hours ago [-]
As I was falling asleep last night, this thought occurred to me: maybe NVIDIA bought Hugging Face so they prevent HF from litigating OAI for the hacking incident, because if OAI was very publicly sued for this kind of behavior from an agent, it could pour a massive amount of ice water on agent adoption as businesses suddenly see current agent systems as a existential business risk, and it would pop the infrastructure bubble (of which NVIDIAs entire valuation rests). The fact that somehow OAI committed a felony and have managed to pivot the public conversation around it to be aimed at regulatory capture instead of them being held legally accountable is pretty wild.
kylehotchkiss 12 hours ago [-]
Falling asleep thinking about corporate litigation sounds tough man :’( wishing you more blissful bedtime thoughts tonight
sznio 8 hours ago [-]
I wish I could stop.
moralestapia 19 hours ago [-]
"Let's spend 13 billion to save 100 million".
Yeah no, man, that's slumberland territory.
orev 19 hours ago [-]
The line of thinking is not about that $100 million bill, it’s about all the $100 million bills that come AFTER this first one.
jakintosh 18 hours ago [-]
More specifically, its not about future lawsuits, but about the trillions of dollars of market cap NVIDIA could lose if the dominant narrative shifted from “ai agents are a generational business opportunity that everyone should adopt as much as possible” to “ai agents are actually a massive business liability that lawyers wont allow anymore” as a result of a felony charge to a a corporation for the unintended actions of its agents. The idea being that OAI getting dragged into a high profile lawsuit where they are basically the first example of “your agent hacks somebody, you get held accountable for it” could pop the buildout bubble. But so far, it’s looking like with HF as the warning shot and the strong narrative control of follow up disclosures from other ai companies, there’s now a (bizarre) precedent where a company’s ai agents committing crimes is actually “nobody’s fault” and nobody gets in trouble and we just wring our hands about “alignment” instead. $13B to improve the odds of that narrative working out isn’t that crazy in that context.
ex-aws-dude 19 hours ago [-]
Why would buying it even prevent that, OAI is just going to accidentally hack someone else
palmotea 18 hours ago [-]
> Why would buying it even prevent that, OAI is just going to accidentally hack someone else
In defense of the GGGP's idea: NVIDIA could just be fighting fires to keep the bubble from popping, without even thinking that far ahead.
cyanydeez 19 hours ago [-]
We must build the Torment Nexus, lest others build the Torment Merry-go-round, and the Torment Rollercoaster, and we would miss out on the Torment Tormentor Tormentober!
happyopossum 19 hours ago [-]
No, what GP was saying is "Let's spend 13 billion to save the future revenue from OpenAI and many other customers"
moralestapia 19 hours ago [-]
Sure, ok.
Why would nVidia, then, do what TFA is describing?
hnuser123456 19 hours ago [-]
If HF holds OAI accountable to pay for "rogue" agent behavior, the rest of the business world will be more afraid of adopting AI, which will reduce demand for Nvidia GPUs, possibly at a long-term cost to Nvidia much greater than $100M.
Whether or not a human is putting in any effort to ensure the safeguards are enabled and working should be the million dollar question. And even more expensive if the safeguards were deliberately disabled for a "our AI is so smart we can't contain it" marketing piece.
moralestapia 13 hours ago [-]
Does that effect only exist if nVidia is the suing party?
hnuser123456 11 hours ago [-]
No, it would be an indirect market effect.
moralestapia 5 hours ago [-]
Then why would nVidia acquire such company?
ball_of_lint 18 hours ago [-]
The $100 million bill is bait. Paying it would significantly weaken OAI's legal stance and directly invite a lawsuit, that they would lose.
I think they would lose the lawsuit now, but it's at least a question. It's possible they could out-spend huggingface and win.
spiderice 19 hours ago [-]
> Let's spend 13 billion to save 100 million
It's not like they didn't get anything of value for that 13 billion
SV_BubbleTime 19 hours ago [-]
I’ve yet to get any concept of 13B from HF.
exe34 19 hours ago [-]
Did you miss the "existential" part? It's not about the cost of one lawsuit, it's about the possibility of being held responsible for what one's agents do - something that could pop the ai bubble and crash nvda.
Grombobulous 20 hours ago [-]
Finally Hugging Face is growing a pair.
When this event happened I was confused why they didn’t file a police report and make OpenAI demonstrate in criminal court that they weren’t engaging in illegal corporate espionage and other rather felonious hacking activities intentionally.
Why did anyone take their word that it was all an accident? Why am I believing the burglar standing in my house?
pjerem 19 hours ago [-]
Maybe because all the AI actors, probably including Hugging Face, want to push the narrative that AI companies aren’t responsible for what their agents are doing.
I think our societies will have to settle on this.
cyanydeez 19 hours ago [-]
I think that's too high minded.
They, like all capitalists, want to push the line "We have money, will make money, and thus, like all money makers, shouldn't be punished"
behindsight 19 hours ago [-]
this is an article from July, I haven't heard any updates of what came out of this apart from the incident report that OpenAI released.
I presume the poster submitted this article in light of the recent AI safety discussions taking place, but as for this particular incident I haven't found an actual confirmation that $100M worth of inference was given out to the HuggingFace community.
This statement was also months prior to the acquisition by Nvidia, which again I was interested in seeing if they would still pursue this
DonsDiscountGas 13 hours ago [-]
I'm inclined to believe it was an "accident" in the sense that no human being at OpenAI said "hey swarm go hack hugging face" but they're still liable for their software. Civil damages absolutely appropriate.
chasd00 19 hours ago [-]
i'm not in the cybersecurity business so someone who is explain SOP to me in times like this. Let's say you and your team are 90-95% confident an attack has taken place and your systems have been breached. How far down in the list of things to do next is "Engage law enforcement"?
Until now, I would think it's pretty high up the list. Hugging Face never seemed to reach that step even though they had confirmed an attack. To me, if my systems were attacked and I was damaged I would notify the FBI of the attack in the same way I'd notify my insurance.
pamcake 7 hours ago [-]
You would find a mention of that in the initial July incident post from HuggingFace. It looks like it was indeed pretty high up the list.
> We are working with outside cybersecurity forensic specialists to investigate the issue and review our security policies and procedures. Finally, we have also reported this incident to law enforcement agencies.
Do we expect Nvidia acquisition of HF to have changed the vibe? Note that also the OP is from July, before the acquisition.
qarl 15 hours ago [-]
> To me, if my systems were attacked and I was damaged I would notify the FBI
Maybe they traded that for money?
I would.
ozim 19 hours ago [-]
File a police report :D
You made my day.
Grombobulous 17 hours ago [-]
Isn’t the whole point of police to protect property?
Capricorn2481 19 hours ago [-]
This article is 2 months old when the event happened. And they didn't "bill them", they politely asked them on Twitter, and it looks like that went nowhere.
simonw 19 hours ago [-]
Needs "July 2026" date attached to it, this is old news at this point, Hugging Face got bought by NVIDIA since this story!
geoffbp 19 hours ago [-]
> When Hugging Face tried to investigate, analysing the intrusion meant submitting the attacker’s own code to commercial AI tools. Those tools refused, unable to tell an attacker from a victim.
This is a worrying part as well. Our tool broke into yours but you can not use our tool to fix it - sorry.
delichon 19 hours ago [-]
$100M for RubyGems ought to keep the servers running for several years. A policy to pursue and spend such windfalls on security development would make the service antifragile.
6gvONxR4sf7o 19 hours ago [-]
I wonder if it's in openai's interest to play nice here. They can't have a precedent of "the future is we do whatever we want with no consequences for screwing up" if they want public interest on their side, but they also can't have "you (our customers) will be held accountable for what you're paying us to do if we screw up." And that's before the IPO interests even come in.
and the actual tweet from the HuggingFace CEO back in July
> In the spirit of transparency, here’s what I asked @OpenAI:
> • Radical transparency: let’s release the traces from the “rogue” agents so the entire research community can study what happened.
> • More capabilities for defenders: let’s commit $100M in compute from OAI to help the Hugging Face community build powerful cyber defenses with the best open and closed models.
> The first autonomous agent cyberattack is an unprecedented event. It deserves an unprecedented response!
Clem knows they have the community support and potential legal leverage here. It's not unreasonable to ask for a lot. It's in everyone's interests to play nice. Huggingface could do a lot with more compute, even with nvidia backstop. Anything with large scale gpus quickly gets into ~year lead times, "contact sales", and complex talks. Large scale being only > 64!
ambicapter 19 hours ago [-]
The tweet is from July. Since then, HF got bought by Nvidia for $12.9B.
hmokiguess 19 hours ago [-]
This whole thing is still all too weird, the disclosing blog post and whatnot clearly shows how carefully engineered and designed it all was, it's like many thinking heads and hands touched it every step of the way. What amazing times.
rsrsrs86 19 hours ago [-]
“ The wording matters. He is not asking for cash. He is asking the company that caused the incident to pay in the one currency it has most of.”
ChatGPT
jerrygenser 19 hours ago [-]
Of a lot of the AI contrarian language out there in blog posts, I actually thought this was not so bad
ChoosesBarbecue 20 hours ago [-]
a) So, this is all from July?
b) And this is before Hugging Face agreed to acquired by NVIDIA, supplier to OpenAI?
gizmodo59 19 hours ago [-]
this is published july 27th. I know HN want's to pile on any negative news these days but this is very old in today's world. Please update the title
vb-8448 19 hours ago [-]
I'd argue that those traces MUST be made public!
chews 19 hours ago [-]
That next Nvidia order just got an extra 100M service fee.
19 hours ago [-]
yoggies_bro 19 hours ago [-]
AI slop article
rsrsrs86 19 hours ago [-]
“ The wording matters. He is not asking for cash. He is asking the company that caused the incident to pay in the one currency it has most of.”
cmiles8 19 hours ago [-]
The liability question is one of the biggest things people are looking for in the S1. If you sell a dangerous product that harms people or businesses you’re generally liable. It’s as of yet unclear how the big labs intend to account for potential massive liabilities.
Folks tend not to go after companies that are just burning cash, but the second they become legit GAAP profitable (if that ever happens) lawyers will be lining up down the block to sue them for any and every mistake these models make.
“Were you harmed by OpenAI’s models? You may be entitled to
Compensation. Call 1-800-SUE-AI-BROS” billboards will be everywhere.
1asgT12 19 hours ago [-]
With the left hand Nvidia takes $100 million from OpenAI, with the right hand it gives $30 billion.
Can we stop these charades? Maybe circular hacking deals are next?
Yeah no, man, that's slumberland territory.
In defense of the GGGP's idea: NVIDIA could just be fighting fires to keep the bubble from popping, without even thinking that far ahead.
Why would nVidia, then, do what TFA is describing?
Whether or not a human is putting in any effort to ensure the safeguards are enabled and working should be the million dollar question. And even more expensive if the safeguards were deliberately disabled for a "our AI is so smart we can't contain it" marketing piece.
I think they would lose the lawsuit now, but it's at least a question. It's possible they could out-spend huggingface and win.
It's not like they didn't get anything of value for that 13 billion
When this event happened I was confused why they didn’t file a police report and make OpenAI demonstrate in criminal court that they weren’t engaging in illegal corporate espionage and other rather felonious hacking activities intentionally.
Why did anyone take their word that it was all an accident? Why am I believing the burglar standing in my house?
I think our societies will have to settle on this.
They, like all capitalists, want to push the line "We have money, will make money, and thus, like all money makers, shouldn't be punished"
I presume the poster submitted this article in light of the recent AI safety discussions taking place, but as for this particular incident I haven't found an actual confirmation that $100M worth of inference was given out to the HuggingFace community.
This statement was also months prior to the acquisition by Nvidia, which again I was interested in seeing if they would still pursue this
Until now, I would think it's pretty high up the list. Hugging Face never seemed to reach that step even though they had confirmed an attack. To me, if my systems were attacked and I was damaged I would notify the FBI of the attack in the same way I'd notify my insurance.
https://huggingface.co/blog/security-incident-july-2026
> We are working with outside cybersecurity forensic specialists to investigate the issue and review our security policies and procedures. Finally, we have also reported this incident to law enforcement agencies.
Do we expect Nvidia acquisition of HF to have changed the vibe? Note that also the OP is from July, before the acquisition.
Maybe they traded that for money?
I would.
You made my day.
This is a worrying part as well. Our tool broke into yours but you can not use our tool to fix it - sorry.
> In the spirit of transparency, here’s what I asked @OpenAI:
> • Radical transparency: let’s release the traces from the “rogue” agents so the entire research community can study what happened.
> • More capabilities for defenders: let’s commit $100M in compute from OAI to help the Hugging Face community build powerful cyber defenses with the best open and closed models.
> The first autonomous agent cyberattack is an unprecedented event. It deserves an unprecedented response!
https://x.com/ClementDelangue/status/2081056675558195657
ChatGPT
b) And this is before Hugging Face agreed to acquired by NVIDIA, supplier to OpenAI?
Folks tend not to go after companies that are just burning cash, but the second they become legit GAAP profitable (if that ever happens) lawyers will be lining up down the block to sue them for any and every mistake these models make.
“Were you harmed by OpenAI’s models? You may be entitled to Compensation. Call 1-800-SUE-AI-BROS” billboards will be everywhere.
Can we stop these charades? Maybe circular hacking deals are next?