Join our Newsletter — 33% off our NHI Course
Home› NHI Breaches› Hugging Face Spaces Breach 2024: How Unauthorised Access…
Breach analysis Incident: 31 May 2024

Hugging Face Spaces Breach 2024: How Unauthorised Access Exposed Secrets Stored for AI Apps

← All NHI breaches
By Lalit Choda, NHI Mgmt Group Updated 29 September 2026 6 min read
Attack route: Not disclosed Identities: API key Secret or password
On this page

At the end of May 2024, Hugging Face said it had detected unauthorised access to its Spaces platform, the service where users host and share machine learning apps and demos. The access related specifically to Spaces secrets, the environment values such as API keys and tokens that app owners store so their Spaces can call other services. Hugging Face said it suspected "a subset of Spaces' secrets could have been accessed without authorization." It revoked the Hugging Face tokens found in those secrets, emailed the users affected and advised everyone to refresh any key or token and move to fine-grained access tokens. It also removed organisation tokens entirely, introduced a key management service for Spaces secrets, expanded its detection and automatic invalidation of leaked tokens, and reported the incident to law enforcement and data protection authorities. Hugging Face did not say how the attacker got in or how many secrets were exposed.

Key takeaways

  • Hugging Face detected unauthorised access to its Spaces platform related to Spaces secrets in late May 2024.
  • It suspected a subset of the secrets users stored for their AI apps had been accessed.
  • Hugging Face revoked tokens found in those secrets and told all users to refresh keys and tokens.
  • It removed organisation tokens, added a key management service for secrets and plans to retire classic tokens.
  • The identity lesson: a hosting platform that stores users' secrets is a shared vault, and its customers must be ready to rotate every key they keep there.

At a glance

OrganisationHugging Face (AI model and app platform) and Spaces users
WhenDetected in the week before 31 May 2024; disclosed 31 May 2024
AttackerUnattributed
Entry pointNot disclosed; unauthorised access to the Spaces platform
Identities abusedSecrets stored in Spaces, including Hugging Face tokens and other keys
ImpactA subset of Spaces secrets suspected accessed; tokens revoked; platform-wide token changes
CategoryNHI, LLM and AI platform. Incident class: confirmed NHI breach (secrets stored on an AI platform accessed)

What happened

Hugging Face disclosed the incident in a short post: "Earlier this week our team detected unauthorized access to our Spaces platform, specifically related to Spaces secrets. As a consequence, we have suspicions that a subset of Spaces' secrets could have been accessed without authorization." Its first step was to revoke "a number of HF tokens present in those secrets," and users whose tokens were revoked received an email. The company advised: "We recommend you refresh any key or token and consider switching your HF tokens to fine-grained access tokens which are the new default."

It then described broader changes: "Over the past few days, we have made other significant improvements to the security of the Spaces infrastructure, including completely removing org tokens (resulting in increased traceability and audit capabilities), implementing key management service (KMS) for Spaces secrets, robustifying and expanding our system's ability to identify leaked tokens and proactively invalidate them, and more generally improving our security across the board." It also said it planned to deprecate classic read and write tokens once fine-grained tokens reached feature parity, and that it was working with outside forensic specialists.

BleepingComputer described Spaces as "a repository of AI apps created and submitted by the community's users, allowing other members to demo them," and noted that Hugging Face had become a target, citing JFrog's discovery earlier in 2024 of about 100 malicious models. SecurityWeek recalled that in late 2023 researchers had found more than 1,600 Hugging Face API tokens exposed in code repositories.

Timeline

DateEvent
Late May 2024Hugging Face detects unauthorised access to Spaces secrets.
31 May 2024Hugging Face discloses the incident and revokes affected tokens.
2 to 3 June 2024BleepingComputer and SecurityWeek report the incident.

How it happened: the identity attack path

  1. Secrets stored on the platform. Spaces owners kept API keys and tokens as secrets for their apps.
  2. Unauthorised access. An attacker gained access to the Spaces platform; the method was not disclosed.
  3. Secrets exposed. A subset of Spaces secrets may have been accessed.
  4. Tokens revoked. Hugging Face revoked HF tokens found in those secrets and notified users.
  5. Platform hardening. Org tokens were removed and secrets moved under a key management service.

Impact

  • Exposed: a subset of Spaces secrets, including Hugging Face tokens; the number was not disclosed.
  • Users: affected users notified by email; all users advised to rotate keys and tokens.
  • Platform: org tokens removed and classic tokens set for deprecation.

What this means for NHI governance

AI app platforms ask users to store secrets so that hosted apps can call model APIs, databases and cloud services. That makes the platform a shared secrets store for thousands of owners, many of whom will not track which keys they put there. When the platform is breached, the only defence is for each owner to rotate everything, and quickly.

For platform users, store only scoped, revocable keys in hosted apps and keep a list of them. For platforms, encrypt secrets with a key management service and offer fine-grained tokens by default, as Hugging Face moved to do. See our LLMjacking Guide and Secrets Management Guide.

Recommendations

Frequently asked questions

What happened in the Hugging Face Spaces breach?

In May 2024, Hugging Face detected unauthorised access to its Spaces platform and suspected that a subset of the secrets users stored for their apps had been accessed.

What did Hugging Face do?

It revoked tokens found in the affected secrets, notified users, removed organisation tokens, added a key management service for secrets and reported the incident to authorities.

Is this the same as the 2026 Hugging Face incident?

No. The 2026 incident involved AI agents during an evaluation and is covered on a separate page.

OpenAI and Hugging Face Breach 2026 · 12,000 Live Secrets in LLM Training Data 2025 · LLMjacking Guide · Secrets Management Guide · Token and Session Security Guide

How NHI Mgmt Group can help

AI platforms hold keys to models, data and cloud services. We help teams scope those keys, track where they are stored and rotate them when a platform is breached. See our NHI and AI agent security training.

References

Free weekly newsletter

Subscribe to the NHI & AI Identity Journal

The latest on NHI and Agentic AI security – articles, research, breaches, news and events every week.

Bonus 33% off our NHI Course when you subscribe.

NHIMG Editorial Note
Written and reviewed by Lalit Choda, NHI Mgmt Group. Last updated 29 September 2026.
Based on the public sources listed under References. Details may change as investigations continue.
NHI Mgmt Group — the #1 independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org