On May 31, 2024, Hugging Face disclosed unauthorized access related to its Spaces platform and said it suspected that a subset of Spaces secrets could have been accessed without authorization. The company revoked a number of HF tokens present in those secrets and recommended refreshing keys or tokens and using fine-grained access tokens. The event is a useful reminder that AI security is not only about model jailbreaks: the surrounding action layer often holds credentials that can reach code repositories, APIs, datasets, models, cloud services, and business systems.
What Hugging Face disclosed
Hugging Face said its team detected unauthorized access to the Spaces platform related to Spaces secrets and suspected that a subset of those secrets could have been accessed. It revoked a number of HF tokens found in those secrets and contacted affected users whose tokens were revoked.
The company also described security changes including removing organization tokens from Spaces, implementing a key management service for Spaces secrets, improving leaked-token detection and proactive invalidation, and moving toward fine-grained access tokens.
Why this is an “AI action-layer” security case
A model may generate text, but an AI application becomes operationally powerful through credentials and tools. Spaces and similar platforms can connect code to models, datasets, Git repositories, storage, inference endpoints, and external APIs. If secrets at that layer are exposed, the risk can move beyond the original AI app.
Model/data access
A token may allow download, upload, or modification of assets.
External APIs
Secrets can authorize SaaS, databases, or business actions outside the AI platform.
CI/CD and code
Repository or deployment credentials may affect software supply chain.
Cloud services
Credentials may reach storage, compute, queues, or other infrastructure.
Fine-grained credentials reduce blast radius
A broad reusable token creates more impact than a credential restricted to one resource and operation. Hugging Face explicitly recommended fine-grained access tokens in its disclosure, and its later security guidance continued to emphasize account and token protections.
- Use a unique token per application or environment.
- Grant the minimum repository, model, dataset, or organization access required.
- Separate read and write credentials.
- Avoid embedding long-lived tokens in code, images, notebooks, prompts, or logs.
- Rotate secrets automatically where possible.
- Revoke credentials immediately when an app or user no longer needs them.
Treat AI app secrets like production infrastructure secrets
Developer-friendly AI platforms can make it easy to add API keys and tokens. Convenience should not turn secrets into ordinary configuration. Use platform secret stores or external KMS-backed systems, restrict who can read or modify secrets, and prevent values from appearing in build logs or runtime errors.
Rotate downstream credentials, not just the first token
If an AI application stores credentials for third-party services, a compromise of the secret store may affect systems beyond the platform itself. Response should identify every secret that was present, determine its scope, rotate or revoke it, and review downstream logs for unauthorized use.
| Secret type | Follow-up question |
|---|---|
| Platform token | Which models, datasets, or repositories could it access? |
| Cloud key | Which accounts, buckets, or services were in scope? |
| SaaS API token | What records or actions were authorized? |
| Database credential | What schemas and networks were reachable? |
| Webhook secret | Could an attacker forge trusted events? |
AI Spaces and apps are part of the software supply chain
AI applications often install Python packages, model artifacts, system libraries, and external code. Secrets and build pipelines therefore sit alongside supply-chain risk. Use pinned dependencies, controlled build images, provenance checks, and isolation between build and runtime environments.
Do not assume a model file, Space, extension, or demo is low risk simply because the primary purpose is experimentation. If it runs code with network access and secrets, treat it as an application workload.
Monitor credentials and downstream behavior
Secret scanning helps find accidental exposure, but runtime monitoring is needed when a valid credential is actually abused. Useful signals include new source networks, new repositories or datasets, unusual download volume, permission changes, and API calls outside the application’s normal pattern.
- Alert on token use from new locations or workloads where supported.
- Track unusual object and dataset enumeration.
- Monitor large downloads or exports.
- Detect access to resources outside the application’s normal set.
- Record secret rotation and revocation events.
- Correlate platform events with downstream API logs.
Govern the AI action layer as an API ecosystem
Organizations should maintain an inventory of AI applications, models, tools, secrets, service accounts, external APIs, and owners. This turns a secret incident from an open-ended investigation into a bounded graph of dependencies.
- Inventory applications and their runtime environments.
- Record every external service and credential class.
- Classify read, write, publish, financial, and administrative permissions.
- Require fine-grained scopes for production.
- Separate development and production credentials.
- Test secret rotation and application recovery.
- Monitor changes to integrations and permissions.
Key lessons from the Hugging Face Spaces incident
- AI security includes conventional secrets and identity engineering.
- Credential scope determines breach blast radius.
- Removing broad organization-level tokens can improve traceability and reduce shared authority.
- KMS-backed secret handling and leaked-token detection are valuable layers.
- Incident response must follow credentials into downstream APIs.
- AI platforms should be included in software-supply-chain and third-party risk programs.
Frequently asked questions
What happened in the 2024 Hugging Face incident?
Hugging Face disclosed unauthorized access related to its Spaces platform and said it suspected that a subset of Spaces secrets could have been accessed without authorization.
Did the incident mean Hugging Face models were compromised?
The public disclosure focused on Spaces secrets and tokens, not a general compromise of model behavior or all models on the platform.
What did Hugging Face recommend?
The company recommended refreshing keys or tokens and using fine-grained access tokens, and it described additional infrastructure and token-security changes.
What is AI action-layer security?
It is the security of the credentials, tools, APIs, storage, code execution, connectors, and workflows that let an AI application read data or take actions beyond model inference.
Why are fine-grained tokens important?
They reduce blast radius by limiting what one credential can access or modify if it is leaked or misused.
Sources and further reading
- Hugging Face — Space secrets leak disclosure — official May 2024 incident disclosure
- Hugging Face — 2024 Security Feature Highlights — platform security controls and token guidance
- OWASP API Security Top 10 — API identity, inventory, and third-party risk context
- NIST Cybersecurity Framework 2.0 — risk governance and incident-management context
Protect APIs with runtime context, not just static rules
Ammune helps security teams discover APIs, understand normal behavior, detect abuse and authorization anomalies, and apply runtime protection across modern API environments.
