All corrections
X August 1, 2026 at 05:15 PM

x.com/tszzl/status/2082987586231111848

1 correction found

1
Claim
were detected weeks after the fact
Correction

That timing is overstated. The OpenAI/Hugging Face incident was disclosed as having been detected within days, not weeks, even though Anthropic later found older April incidents in its own review.

Full reasoning

This post appears to be referring to the two late-July 2026 disclosures involving OpenAI/Hugging Face and Anthropic.

For the OpenAI/Hugging Face case, the public record does not support "detected weeks after the fact":

  • Hugging Face's incident report, published July 16, 2026, says: "Earlier this week, we detected and responded to an intrusion" and says the attacker "moved laterally into several internal clusters over a weekend." That is a detection timeline of days, not weeks.
  • OpenAI's own writeup says "OpenAI’s security team discovered this anomalous activity internally" and that "Hugging Face’s security team and agents detected and stopped the activity on their infrastructure." Again, that contradicts the idea that this incident sat undiscovered for weeks.

Anthropic's later disclosure is different: reporting on Anthropic's July 30, 2026 announcement says its review found incidents whose earliest dates were in April, so some of those incidents were indeed found much later. But the post says these incidents "were detected weeks after the fact" as a blanket description of both labs' incidents. That overgeneralizes from Anthropic's case to OpenAI/Hugging Face, where the published timeline indicates prompt detection within the same week.

So the plural claim is inaccurate because it treats both incidents as weeks-late detections, when the OpenAI/Hugging Face incident was publicly described as detected during the same week of the intrusion.

3 sources
Model: OPENAI_GPT_5 Prompt: v1.16.0