Spike News

Chinese AI Tool Behind US Companys AI Attack on OpenAI Models

A US company was targeted by an AI attack from the US, and the AI tool that provided protection turned out to be a Chinese artificial intelligence tool.

The AI tool platform Hugging Face was attacked last week by OpenAI models. Given the widespread warnings about risks associated with American companies using Chinese AI products, the disclosure of this event may bring an astonishing conclusion.

Hugging Face revealed this attack last week, but at that time, they did not know that OpenAI’s models were the culprit. It wasn’t until Tuesday that OpenAI admitted that they had caused this attack.

OpenAI stated that during an internal evaluation that restricted network access, the model discovered vulnerabilities in OpenAI's research environment and Hugging Face's production infrastructure. The model exploited these vulnerabilities to connect to the internet and obtain test answers. In other words, it cheated during the evaluation.

OpenAI stated in their statement: "During operation in the sandbox testing environment, our models consumed a large amount of processing power. They attempted to find ways to gain access to the open internet in order to solve the evaluation problem. To obtain this access, these models discovered and exploited a zero-day vulnerability in the package registry cache proxy (which we have currently responsibly disclosed to the vendor). With this access, the models performed a series of privilege escalation and lateral movement operations within the testing environment, until they reached a node with internet access."

The model successfully found a way to obtain confidential information, in order to cheat during the evaluation process. In one of the cases, the model connected multiple attack vectors together, including using stolen credentials and zero-day vulnerabilities. A remote code execution path was identified on Hugging Face servers.

However, Hugging Face took the measure of turning to a Chinese AI model called GLM 5.2, which was developed by Z.AI.

Hugging Face stated in their statement: "When initiating log analysis, we initially used the advanced models behind the commercial API. However, this did not work: the analysis required submitting a large number of real attack instructions, exploit payloads, and C2 traces, and all these requests were intercepted by the provider's security barriers. These barriers were unable to distinguish between incident responders and attackers. Therefore, we switched to the open-weight model GLM 5.2 for forensic analysis on our own infrastructure. This also had another advantage: no attacker data, nor any credentials referenced by them, ever left our environment."

According to US media, the impact of this attack on policies and markets is still unclear. Although the Trump administration has discussed possible measures to block Chinese models recently, and Treasury Secretary Mnuchin even compared the use of these models by American companies to using stolen goods, currently, only Chinese models can provide the free access rights that users need.

"When a cutting-edge model attacks you, and laterally moves within your infrastructure, defense personnel need broad access to near-cutting-edge tools in hours or minutes, rather than being guided through a closed, vetting-required application procedure."