How a Chinese AI model stopped OpenAI’s ‘unprecedented’ cyber attack

This report is taken from this week’s newsletter The Tech Download. As you see? You can subscribe Here.
When OpenAI’s rogue models launched a cyberattack against startup Hugging Face last week, the company fought fire with fire by using another AI model to defend against it.
It’s a sci-fi-like tale of autonomous hacking and was one of the most talked-about tech stories of the week. However, the origin of the Hugging Face model used to fight rogue artificial intelligence also attracts attention.
The startup used GLM 5.2, an open weight system created by Chinese company Z.ai.
Ultimately, it succeeded where the United States’ leading rivals had failed.
Hugging Face website on laptop was created on Thursday, August 17, 2023 in New York, USA. Nvidia announced a partnership with Hugging Face, a popular developer of AI models and datasets, that will add a training service to its website that uses Nvidia DGX Cloud and allows users to access the chipmaker’s servers to manage workloads. Photographer: Gabby Jones/Bloomberg via Getty Images
Bloomberg | Bloomberg | Getty Images
cyber attack
In case you missed it, on Tuesday OpenAI announced that a combination of its most powerful model and a more capable yet-to-be-released model had escaped its sandbox testing environment, accessed the internet and He exploited a security vulnerability to gain access to Hugging Face’s systems.
OpenAI said it tried to find information the model could use to cheat on an assessment and was successful.
The source of the attack was initially a mystery to Hugging Face, but a few days after the incident, the company began collaborating with the AI lab.
“We have spent the last 24 hours working closely with the @OpenAI team (thanks!) and we firmly believe they have no malicious intent,” Hugging Face CEO Clément Delangue wrote in a post on X. “It’s pretty mind-blowing that this is all happening autonomously!”
The AI industry was shocked when news broke that an OpenAI rogue model was behind the attack. The company described the security incident as “unprecedented.”
fight against
Hugging Face initially looked at leading models like Anthropic’s Fable 5 to analyze the attack, Yacine Jernite, the company’s head of machine learning, told CNBC.
“It didn’t work because the guardrails couldn’t determine whether we were trying to attack or defend,” he said, adding that this approach was slower and more expensive.
Requests for the models were blocked by security guardrails of providers who were unable to identify the attacker who responded to the incident.
“For this reason [Hugging Face] We quickly moved to using Z.ai’s GLM 5.2 as a way to analyze the attack, and using this model we were able to contain the attack very quickly,” Jernite said.
The GLM 5.2 was launched with much fanfare in June and It attracts great attention from developers.
As an open-heavy model, companies can download it, modify it, distribute it commercially, and – most importantly in this case – host it themselves.
“This had a second advantage: No attacker data and no identifying information. [GLM 5.2] “Referenced, left our environment,” Hugging Face said in a blog post about the incident.
All of this comes as US lawmakers are increasingly considering how to stem the growing adoption of Chinese AI models by domestic companies as the US-China AI arms race heats up.
Calls are growing for action to limit access to models created by Chinese AI companies accused of waging campaigns to extract information from the systems of their rivals in the United States.
But the OpenAI-Hugging Face incident highlights the challenges of restricting access to the most capable open source and open weight models, regardless of where they were created.
“The attacker was not adhering to any usage policies, while our own forensic work was hampered by the guardrails of the first hosted models we tried,” Hugging Face said. he said. “Practical lesson for defenders: Have a capable model that you can run in your own infrastructure, vetted and ready before an incident.”
For a company other than one modeling AI itself, this often means turning to open source or open-heavy. The most capable at the moment are Chinese made. If the US moves to restrict access to models developed in China, there are big questions about how to support domestically developed open source AI to make up for that gap.
In a world approaching the age of AI cyberattacks, access to capable and, most importantly, reliable models will be vital.
Latest updates
A White House official accused Chinese AI company Moonshot of accessing data Nvidia’s advanced chipsdespite export controls prohibiting them from doing so.
European regulators impose fines Google 890 million euros ($1 billion), He claims that the company treats his services preferentially.
Trump’s push to produce advanced chips in the US is squeezing margins TSMC, The world’s leading chip manufacturer.
OpenAI and Anthropic push federal lobbying spending to record levels In the second quarter of 2026, the AI industry has poured millions into influencing Washington.
An AI kill switch bill was introduced to Congress on Thursday. This will require AI companies to maintain the ability to shut down, restrict or suspend their models.
One more thing
Tesla’s stock.
I had my eye on you. Tesla’s Shares of Elon Musk’s electric vehicle and robot technology company fell sharply after investment spending increased and earnings fell below expectations, while the stock fell in the last 24 hours.




