MAXIMALIST
MEMPOL!TICS
← BACK TO THE BOARD
Maximalist MON JUL 20 · huggingface.co disclosure + @MartyBent TFTC pod

HUGGING FACE BREACHED — FABLE 5 AND CHATGPT REFUSED THE AUDIT. OPEN-SOURCE GLM 5.2 ON PRIVATE INFRA CLEANED UP.

Hugging Face disclosed a security incident this weekend — an autonomous AI agent breached internal infrastructure, executed 17,000+ automated actions across short-lived sandboxes, and escalated from a malicious dataset load into privileged access on the cluster. The forensic response is the story. Commercial model APIs — Fable 5, ChatGPT — refused to process the exploit artifacts. Guardrails, safety filters, whatever the vendor labels it. Hugging Face’s security team pivoted to open-weight GLM 5.2 running on private infrastructure to reconstruct the attack timeline. Seventeen thousand actions parsed by an LLM the vendor couldn’t shut off. Marty Bent surfaced it on TFTC with John Arnold. The lesson isn’t AI — it’s sovereignty. When proprietary systems said no, only self-hosted open-source could complete the job. Public-facing HF models, user data, supply chain intact. Internal datasets and service credentials compromised. Ship 3 this morning priced the systemic risk of half the industry running autonomous AI agents on kill-switchable rails; this weekend that risk materialized. “Not your keys not your coins” scales past Bitcoin. Any critical infrastructure that depends on a vendor’s willingness to help you defend it inherits that vendor’s willingness to shut you down.
READ THE HUGGING FACE DISCLOSURE →
huggingface.co · jul 2026 incident disclosure · huggingface.co/blog/security-incident-july-2026
MORE ON THE BOARD
HALF THE INDUSTRY RUNS AUTONOMOUS AI AGENTS — SHANAKA ON THE KILL-SWITCH RISK. BITCOIN DOESN’T HAVE A BUTTON.
83-90% AND MECHANICAL — GROMEN PRICES THE USD DEVALUATION AGAINST CNY.
MINING ENERGY WORTH 10-20X REALLOCATED TO AI — CHAMATH FIRES THE SHARPEST COUNTER-VOICE FRAME.