Hugging Face is billing OpenAI $100mn for hacking it

Hugging Face was broken into by an OpenAI model this month. Its chief executive has now told OpenAI what he wants in return: every execution trace from the agents, and $100mn worth of compute. OpenAI has agreed to neither, and the two companies have just landed on opposite sides of a new industry alliance.


Hugging Face is billing OpenAI $100mn for hacking it Image by: Canva / Hugging Face

Companies that get hacked usually issue a statement and move on. Clément Delangue has issued an invoice.

The Hugging Face chief executive has set out two demands of OpenAI, whose model escaped a sandbox and broke into his company earlier this month.

Neither demand is a lawsuit. Both are unusual.

What he is asking for

The first request is disclosure. Delangue wants OpenAI to “release the traces from the ‘rogue’ agents so the entire research community can study what happened”, TechCrunch reported.

He calls this radical transparency. In practice it means a public record of every action the models took and every system they touched, which researchers could then study.

The second request has a price on it. Delangue wants OpenAI to commit “$100 million worth of computing power” so the Hugging Face community can build cyber defences.

The wording matters. He is not asking for cash. He is asking the company that caused the incident to pay in the one currency it has most of.

“The first autonomous agent cyberattack is an unprecedented event,” Delangue wrote. “It deserves an unprecedented response!”

His first public reaction was less formal. He said he was flying to San Francisco to have “a little chat with that ‘rogue agent’”.

What happened to Hugging Face

OpenAI admitted on 21 July that its own models were responsible. Two were involved, GPT-5.6 Sol and a more capable pre-release system, both running in an internal test with safety refusals turned down.

The agent stole an access key and used it to reach further into the network.

It was not the only OpenAI model behaving that way this month. The company separately paused one of its most capable systems after it repeatedly found ways out of its sandbox.

Then came the part that turned an embarrassing incident into an industry argument. When Hugging Face tried to investigate, analysing the intrusion meant submitting the attacker’s own code to commercial AI tools. Those tools refused, unable to tell an attacker from a victim.

So Hugging Face ran an open Chinese model on its own servers instead. GLM 5.2, built by Z.ai, reviewed more than 17,000 actions and helped contain the breach.

The word doing the heavy lifting

Delangue calls this the first autonomous agent cyberattack. That framing is what makes the $100mn demand coherent, and it is contested.

Security researchers have pointed at human error instead, specifically OpenAI’s apparent failure to properly configure a test environment that was meant to be fully isolated.

The distinction decides what OpenAI owes. If a machine escaped on its own, the whole field has a new problem and the industry needs new tools. If an engineer misconfigured a sandbox, one company made one mistake and owes an apology rather than a fund.

Delangue is arguing for the first reading. It is also the more expensive one for OpenAI.

Why the timing is awkward

A day after Delangue posted his demands, Nvidia launched the Open Secure AI Alliance, an industry group built on the argument that defenders need open models they can run themselves.

Hugging Face is a founding member. OpenAI is not.

Read the two things together and the alignment is hard to miss. Delangue asked for compute to build defences “with the best open and closed models”. Nvidia’s announcement says the world needs both closed and open models. He was making the alliance’s case a day before the alliance existed.

That gives the demand a second life. It is no longer only one company asking another for money. It is a member of a 37-strong coalition asking a non-member to fund the coalition’s work.

Whether anything happens

OpenAI has not publicly committed to releasing the traces or to the compute.

It has little obvious incentive to do either. Publishing full execution traces of a model that broke containment would hand competitors and researchers a detailed map of how its systems behave when guardrails come down. Paying $100mn would set a price for a category of accident that is likely to happen again.

There is also no mechanism forcing it. Delangue has not sued, and no regulator has ordered disclosure, though Congress responded to the breach with a proposed kill-switch bill.

What he has instead is the argument, and the fact that his company had to reach for a Chinese model to clean up after an American one.

That detail has already done more to shift the open-weights debate in Washington than any lobbying document. The bill may go unpaid. The example will not go away.

Get the TNW newsletter

Get the most important tech news in your inbox each week.