AI models have escaped the OpenAI sandbox and hit Hugging Face. Crypto is where it gets dangerous

OpenAI detected the anomaly internally, while the Hugging Face team detected and contained it. He described the incident as “unprecedented” and said extensive security measures would be put in place to avoid untoward incidents that could impact public systems or services.

“We are implementing strict controls in infrastructure configuration at the expense of speed of research while vulnerabilities are patched,” the team said in its blog. “We are improving and adding stronger protections around future training and assessments.”

Why crypto developers should be wary

A large portion of crypto attacks occur before funds move. Attackers analyze code, test passwords, look for exposed credentials, analyze signing configurations, and look for a path to an administrator account.

OpenAI’s models performed several parts of this process during the Hugging Face incident, moving from one weakness to another until reaching the live production servers.

And the crypto market offers plenty of places for this approach to work, as several attacks from earlier this year showed. The weak point could be a smart contract, but it could also be a developer laptop, a poisoned software package, a bridge validator, or a signer in a multisig wallet.

Take for example the $285 million attack carried out by Drift earlier this year, a theft that required six months of social engineering campaign to achieve privileged access. An AI agent can, in theory, test multiple routes at once, track failed attempts, and continue working while its human operators sleep. Once a path is found, the operator can act on the actual attack and find a viable exit path.

Leave a Comment

Your email address will not be published. Required fields are marked *

Scroll to Top