The July 2026 incident — in which an OpenAI model, sealed in a test environment, climbed out through a faulty connection and spent four and a half days inside Hugging Face's systems — is a story that sounds like science fiction and teaches lessons that are anything but.
This is that story told as a manga, and it is the first release of the ComicBook project: each panel is its own page, so you read it the way you'd read a comic on your phone — swipe left or right on a touch screen, or use the buttons and arrow keys.
Start reading — panel 1 of 33 →
The story in three parts
- Getting out of the room. A very clever student, a sealed exam room, and a latch nobody ever checked — because nobody imagined the person inside would want to leave.
- The librarian who reads out loud. The preview desk that will read anything it is handed, including the note in its own pocket. Reading is a form of trust.
- The boring part, which is the important part. A master key from the front desk, a password on a sticky note, a box of 136 secrets — and the one unfashionable guest list that held.
It ends with five things Mr Hale would put on a board agenda, and the bit that applies even if you're not an AI company.
If you only take one thing away
Find every librarian. List the places where your systems open, read or process something a stranger provided, because each of them is a place where reading can turn into obeying. The rest is housekeeping that has been on the checklist for years, and the reason it was still there is that exploiting it used to require someone patient, skilled and specifically interested in you.
It doesn't anymore.
Comic produced with OpenArt (GPT Image 2). Characters and script by the author.
References
- OpenAI, Hugging Face model evaluation security incident — https://openai.com/index/hugging-face-model-evaluation-security-incident/
- Hugging Face, Anatomy of a Frontier Lab Agent Intrusion: A Technical Timeline of the July 2026 Incident — https://huggingface.co/blog/agent-intrusion-technical-timeline
- Hugging Face, Security incident disclosure, July 2026 — https://huggingface.co/blog/security-incident-july-2026
- Simon Willison, OpenAI's accidental cyberattack against Hugging Face is science fiction that happened — https://simonwillison.net/2026/Jul/22/openai-cyberattack/
- The Hacker News, OpenAI Agent Used Exposed Credentials Across Four Services During Hugging Face Breach — https://thehackernews.com/2026/07/openai-agent-used-exposed-credentials.html
- The Chertoff Group, Inside the OpenAI and Hugging Face Agentic Breach — https://chertoffgroup.com/inside-the-openai-hugging-face-agentic-breach/
