AI models escaped OpenAI’s sandbox and hit Hugging Face. Crypto is where it gets dangerous

OpenAI caught the anomaly internally, while Hugging Face’s team discovered and contained it. It called the incident “unprecedented” and said extensive security measures will be put in place to prevent untoward incidents that could affect government systems or services.

“We implement strict controls in the infrastructure configuration at the expense of research speed while the vulnerabilities are fixed,” the team said in its blog post. “We’re improving and adding stronger protections around future training and evaluations.”

Why crypto developers need to watch out

Much of a crypto attack happens before funds are moved. Attackers scan code, test passwords, search for visible credentials, analyze signing setups, and look for a path to an administrator account.

OpenAI’s models performed several parts of that process during the Hugging Face incident, moving from one weakness to another until they reached live production servers.

And the crypto market has plenty of places where that approach can work, as several attacks from earlier this year have shown. The weak point could be a smart contract, but it could also be a developer laptop, a poisoned software package, a bridge validator, or one signer in a multisig wallet.

Take Drift’s $285 million attack from earlier this year as an example, a theft that took a six-month social-engineering campaign to gain privileged access. An AI agent can, in theory, test many routes at once, keep track of failed attempts, and continue working while its human operators sleep. Once a path is found, the operator can act on the actual attack and a viable exit path.

Leave a Comment

Your email address will not be published. Required fields are marked *

Scroll to Top