TL;DR: Exposed API credentials can extend from code repositories into model, dataset, and supply-chain compromise, according to Lasso Security, which found 1,681 valid Hugging Face and GitHub tokens, including 655 with write permissions, and mapped access across 723 organisation accounts. Hard-coded tokens turn LLM platforms into identity-risk amplifiers, not just development tools.
Editorial analysis by NHI Mgmt Group, based on content published by Lasso Security: “+1500 HuggingFace API Tokens were exposed, leaving millions of Meta-Llama, Bloom, and Pythia users vulnerable”.
By the numbers:
- Lasso Security found 1,681 valid tokens through Hugging Face and GitHub.
- The researchers mapped access across 723 organisation accounts.
- They identified 655 users’ tokens with write permissions.
Key questions
Q: What breaks when LLM platform tokens are exposed in public code or repositories?
A: Exposed tokens turn repository content into an authentication source.
Q: Why do write-capable AI platform tokens create more risk than read-only tokens?
A: Read-only tokens can expose sensitive assets, but write-capable tokens can alter them.
Q: How can security teams detect AI credential abuse before it becomes a campaign?
A: Look for abnormal model usage, sudden changes in call volume, repeated access from unfamiliar contexts, and activity that crosses normal session boundaries.
Practitioner guidance
- Restrict model-platform tokens to the minimum required scope Issue separate credentials for read, write, and administrative actions, and avoid reusing the same token across model hosting, dataset access, and automation workflows.
- Inventory exposed AI platform credentials Scan repositories, issue trackers, and CI logs for Hugging Face and GitHub tokens, then revoke any credential that can reach private models or datasets.
- Add validation checks before release Make token detection part of code review and pre-merge controls so hard-coded credentials are blocked before they reach public repositories.
Bottom line: Exposed Hugging Face and GitHub tokens can move beyond simple secret leakage and become a supply chain integrity issue for LLM platforms.
Explore further
View Full Forum → | NHI Foundation Course → | Our Services → | Read the full analysis →
Hard-coded AI platform tokens are now identity assets, not just secrets: The article shows that a leaked Hugging Face token can expose ownership, membership, and permission data, which means the token is carrying a live delegation relationship. That makes it an NHI governance object with lifecycle, scope, and revocation requirements. Practitioners should treat model registry tokens as controlled identities that need assignment and offboarding discipline.
A few things that frame the scale:
- The average estimated time to remediate a leaked secret is 27 days, despite 75% of organisations expressing strong confidence in their secrets management capabilities, according to The State of Secrets in AppSec.
- Organisations maintain an average of 6 distinct secrets manager instances, creating fragmentation that undermines centralised control, according to The State of Secrets in AppSec.
A question worth separating out:
Q: Should organisations treat model registries differently from other code platforms?
A: Yes, because model registries can carry both identity privileges and supply-chain impact at the same time. A leaked token may not just expose a repository; it can change the artifact that hundreds of downstream users trust. That means model registries need IAM, NHI, and software supply-chain controls together, not in separate silos.
👉 Read our full editorial: Exposed Hugging Face tokens show how LLM supply chains fail
Exposed model-hosting tokens are now a supply chain governance problem, not a narrow secrets issue. When a single bearer token can read private assets, modify repositories, and influence what downstream teams download, it crosses from credential hygiene into supply chain integrity. The governance unit is no longer the repository alone but the full model distribution path. Practitioners should treat model platform credentials as part of the software and AI supply chain.
A few things that frame the scale:
- The blast radius of the Salesloft-Drift OAuth supply chain attack was 10 times greater than earlier incidents in which attackers breached Salesforce directly.
A question worth separating out:
Q: Should organisations treat Hugging Face and GitHub access as the same governance problem?
A: Yes, when the same token can move from code exposure to model or dataset access. The governance issue is the shared identity path, not the platform name. Teams should align token inventory, scope, and revocation rules across both environments so a leak in one does not become a trust failure in the other.
👉 Read our full editorial: Exposed Hugging Face tokens show how LLM supply chains fail