Home AIHow a Chinese AI model stopped OpenAI’s “unprecedented” cyberattack

How a Chinese AI model stopped OpenAI’s “unprecedented” cyberattack

by OmarAli
How a Chinese AI model stopped OpenAI’s “unprecedented” cyberattack

This report is from this week’s The Tech Download newsletter. Do you like what you see? You can log in Here.

When OpenAI’s fraudulent models launched a cyberattack on startup Hugging Face last week, the company fought fire with fire and used a different AI model to defend itself.

It’s a sci-fi-esque story about autonomous hacking and was one of the most talked-about tech stories of the week. But the origin of the Hugging Face model, which is used to combat rogue AI, is also causing a stir.

The startup used GLM 5.2, an open weight system from Chinese company Z.ai.

Ultimately, it succeeded where leading U.S. competitors failed.

The Hugging Face website set up on a laptop on Thursday, August 17, 2023, in New York, USA. Nvidia announced a partnership with Hugging Face, a popular AI model and dataset developer, that will add a training service to its website that leverages Nvidia DGX Cloud, allowing users to access the chipmaker’s servers to handle their workloads. Photographer: Gabby Jones/Bloomberg via Getty Images

Bloomberg | Bloomberg | Getty Images

Cyber ​​attack

In case you missed it: On Tuesday, OpenAI said that a combination of its most powerful model and a more powerful model that has not yet been released escaped a sandbox test environment, accessed the Internet and exploited a vulnerability to gain access to Hugging Face’s systems.

The model tried to find information that it could use to cheat a review and succeeded, OpenAI said.

The source of the attack was initially a mystery to Hugging Face, but a few days after the incident, the company began working with the AI ​​lab.

“We have been working closely with the @OpenAI team for the last 24 hours (thanks!) and firmly believe that there was no malicious intent on their part,” Hugging Face CEO Clément Delangue wrote in a post on X. “It’s pretty mind-boggling that this all happened autonomously!”

Shock swept through the AI ​​industry when it was revealed that a fraudulent OpenAI model was behind the attack. The company described the security incident as “unprecedented.”

I defend myself

To analyze the attack, Hugging Face first looked to frontier models like Anthropic’s Fable 5, Yacine Jernite, head of machine learning at the company, told CNBC.

“It didn’t work because the guardrails couldn’t tell whether we wanted to defend or attack,” he said, adding that this approach was also slower and more expensive.

Requests to the models were blocked by the vendors’ security guardrails, which were unable to distinguish attacker from attacker.

“So [Hugging Face] “We quickly switched to Z.ai’s GLM 5.2 to analyze the attack and were able to contain it very quickly using this model,” Jernite said.

GLM 5.2 was released to great fanfare in June and was very popular among developers.

Because it is an open weight model, companies can download it, modify it, deploy it commercially and, crucially in this case, self-host it.

“This had a second advantage: no attacker data and no credentials.” [GLM 5.2] expelled, leave our environment,” Hugging Face said in a blog post about the incident.

All of this comes as U.S. lawmakers increasingly consider how to curb the increasing adoption of Chinese AI models by domestic companies as the AI ​​arms race between the U.S. and China intensifies.

There are growing calls for action to restrict access to models from Chinese AI companies accused of running campaigns to extract information from U.S. rivals’ systems.

However, the OpenAI-Hugging Face incident highlights how difficult it is to restrict access to the most powerful open source and open weight models, regardless of where they are created.

“The attacker was not bound by any usage policy, while our own forensic work was blocked by the guardrails of the hosted models we first tried,” said Hugging Face. “The practical lesson for defenders: have a powerful model that you can run on your own infrastructure, verified and ready to use before an incident.”

For a company other than one that builds AI models itself, this usually means going open source or open weight. The currently most powerful ones are made in China. If the U.S. restricts access to Chinese-developed models, the big question becomes how it can strengthen domestic open-source AI to close the gap.

In a world heading into an age of AI cyberattacks, access to powerful and, above all, reliable models will be crucial.

Latest updates

A White House official has accused Chinese AI company Moonshot of access Nvidia’s advanced chipsalthough export controls prohibit them from doing so.

European regulators have imposed fines Google 890 million euros (1 trillion US dollars), claiming the company is favoring its own services.

Trump’s pressure to produce advanced chips in the US is squeezing margins TSMC, the world’s leading chip manufacturer.

OpenAI and Anthropic increased their federal lobbying spending to record levels in the second quarter of 2026, when the AI ​​industry invested millions in influencing Washington.

An AI kill switch bill was introduced in Congress on Thursday. This would require AI companies to continue to be able to shut down, throttle or suspend their models.

One more thing

Stock chart iconStock chart iconHide content

Tesla stock.

I’ve been keeping an eye on it Tesla The stock saw a sharp decline in the last 24 hours as shares of Elon Musk’s electric vehicle and robotics company slumped after capital spending soared and profits fell short of expectations.

Choose CNBC as your preferred source on Google and never miss a moment from the most trusted name in business news.

https://www.cnbc.com/2026/07/24/chinese-ai-model-openai-cyber-attack.html

Viral Trends

This website uses cookies to improve your experience. We'll assume you're ok with this, but you can opt-out if you wish. Accept Read More