At the end of May 2024, Hugging Face said it had detected unauthorised access to its Spaces platform, the service where users host and share machine learning apps and demos. The access related specifically to Spaces secrets, the environment values such as API keys and tokens that app owners store so their Spaces can call other services. Hugging Face said it suspected "a subset of Spaces' secrets could have been accessed without authorization." It revoked the Hugging Face tokens found in those secrets, emailed the users affected and advised everyone to refresh any key or token and move to fine-grained access tokens. It also removed organisation tokens entirely, introduced a key management service for Spaces secrets, expanded its detection and automatic invalidation of leaked tokens, and reported the incident to law enforcement and data protection authorities. Hugging Face did not say how the attacker got in or how many secrets were exposed.
Key takeaways
- Hugging Face detected unauthorised access to its Spaces platform related to Spaces secrets in late May 2024.
- It suspected a subset of the secrets users stored for their AI apps had been accessed.
- Hugging Face revoked tokens found in those secrets and told all users to refresh keys and tokens.
- It removed organisation tokens, added a key management service for secrets and plans to retire classic tokens.
- The identity lesson: a hosting platform that stores users' secrets is a shared vault, and its customers must be ready to rotate every key they keep there.
At a glance
| Organisation | Hugging Face (AI model and app platform) and Spaces users |
|---|---|
| When | Detected in the week before 31 May 2024; disclosed 31 May 2024 |
| Attacker | Unattributed |
| Entry point | Not disclosed; unauthorised access to the Spaces platform |
| Identities abused | Secrets stored in Spaces, including Hugging Face tokens and other keys |
| Impact | A subset of Spaces secrets suspected accessed; tokens revoked; platform-wide token changes |
| Category | NHI, LLM and AI platform. Incident class: confirmed NHI breach (secrets stored on an AI platform accessed) |
What happened
Hugging Face disclosed the incident in a short post: "Earlier this week our team detected unauthorized access to our Spaces platform, specifically related to Spaces secrets. As a consequence, we have suspicions that a subset of Spaces' secrets could have been accessed without authorization." Its first step was to revoke "a number of HF tokens present in those secrets," and users whose tokens were revoked received an email. The company advised: "We recommend you refresh any key or token and consider switching your HF tokens to fine-grained access tokens which are the new default."
It then described broader changes: "Over the past few days, we have made other significant improvements to the security of the Spaces infrastructure, including completely removing org tokens (resulting in increased traceability and audit capabilities), implementing key management service (KMS) for Spaces secrets, robustifying and expanding our system's ability to identify leaked tokens and proactively invalidate them, and more generally improving our security across the board." It also said it planned to deprecate classic read and write tokens once fine-grained tokens reached feature parity, and that it was working with outside forensic specialists.
BleepingComputer described Spaces as "a repository of AI apps created and submitted by the community's users, allowing other members to demo them," and noted that Hugging Face had become a target, citing JFrog's discovery earlier in 2024 of about 100 malicious models. SecurityWeek recalled that in late 2023 researchers had found more than 1,600 Hugging Face API tokens exposed in code repositories.
Timeline
| Date | Event |
|---|---|
| Late May 2024 | Hugging Face detects unauthorised access to Spaces secrets. |
| 31 May 2024 | Hugging Face discloses the incident and revokes affected tokens. |
| 2 to 3 June 2024 | BleepingComputer and SecurityWeek report the incident. |
How it happened: the identity attack path
- Secrets stored on the platform. Spaces owners kept API keys and tokens as secrets for their apps.
- Unauthorised access. An attacker gained access to the Spaces platform; the method was not disclosed.
- Secrets exposed. A subset of Spaces secrets may have been accessed.
- Tokens revoked. Hugging Face revoked HF tokens found in those secrets and notified users.
- Platform hardening. Org tokens were removed and secrets moved under a key management service.
Impact
- Exposed: a subset of Spaces secrets, including Hugging Face tokens; the number was not disclosed.
- Users: affected users notified by email; all users advised to rotate keys and tokens.
- Platform: org tokens removed and classic tokens set for deprecation.
What this means for NHI governance
AI app platforms ask users to store secrets so that hosted apps can call model APIs, databases and cloud services. That makes the platform a shared secrets store for thousands of owners, many of whom will not track which keys they put there. When the platform is breached, the only defence is for each owner to rotate everything, and quickly.
For platform users, store only scoped, revocable keys in hosted apps and keep a list of them. For platforms, encrypt secrets with a key management service and offer fine-grained tokens by default, as Hugging Face moved to do. See our LLMjacking Guide and Secrets Management Guide.
Recommendations
- Store only scoped keys on hosting platforms. Give each app a key limited to what it needs. See our LLMjacking Guide.
- Use fine-grained tokens. Replace broad read and write tokens with narrowly scoped ones. See the Token and Session Security Guide.
- Keep an inventory of secrets placed with vendors. Know what to rotate when a platform reports a breach. See the Third-Party Access Guide.
- Rotate on notice. Refresh every key stored on the platform, not only those the vendor revoked. See the Leaked Credential Response Playbook.
- Monitor key usage. Watch for API calls from unexpected places after an incident. See the AI Infrastructure Workload Identity Guide.
Frequently asked questions
What happened in the Hugging Face Spaces breach?
In May 2024, Hugging Face detected unauthorised access to its Spaces platform and suspected that a subset of the secrets users stored for their apps had been accessed.
What did Hugging Face do?
It revoked tokens found in the affected secrets, notified users, removed organisation tokens, added a key management service for secrets and reported the incident to authorities.
Is this the same as the 2026 Hugging Face incident?
No. The 2026 incident involved AI agents during an evaluation and is covered on a separate page.
Related NHI Mgmt Group resources
OpenAI and Hugging Face Breach 2026 · 12,000 Live Secrets in LLM Training Data 2025 · LLMjacking Guide · Secrets Management Guide · Token and Session Security Guide
How NHI Mgmt Group can help
AI platforms hold keys to models, data and cloud services. We help teams scope those keys, track where they are stored and rotate them when a platform is breached. See our NHI and AI agent security training.