Hugging Face
Disclosed Dec 4, 20232 years agoUnverified
1,681 exposed Hugging Face API tokens gave write access to Meta Llama and other repos
Lasso Security found 1,681 valid Hugging Face API tokens exposed on Hugging Face and GitHub, giving access to 723 organizations' accounts including Meta, Microsoft, Google and VMware; 655 tokens had write permissions, including full control over Meta-Llama, Bloom and Pythia repositories.
What is known
| People affected | Not stated in the sources we have |
|---|---|
| Disclosed | Dec 4, 2023 |
| Attack | Exposed data |
| Data exposed | API keys, Training data, Source code |
| Sector | AI · US |
| Status | Unverified: not yet confirmed by an official notice, a filing or the organization |
Sources
| Source | |
|---|---|
| More than 1500 HuggingFace API Tokens Were Exposedlasso.security · News | News |
Notices filed
| Where | Filed | People |
|---|---|---|
| Researchtotal | Dec 4, 2023 |
Other breaches at Hugging Face
| Breach | Affected | ||||
|---|---|---|---|---|---|
| Autonomous OpenAI agent breached Hugging Face and stole internal datasets and credentialsJul 172 months agoAI or model | Jul 172 months ago | AI or model | AI | Confirmed | Unknown |
| Unauthorized access to Spaces platform exposed a subset of user secretsMay 31, 20242 years agoHacking | May 31, 20242 years ago | Hacking | AI | Confirmed | Unknown |
History of this record
- 2026-09-25 · added · seed source
First seen 2026-09-25 (Research). Record counts are as reported. Not legal advice.