HuggingFace Responds to Spaces Security Incident
Key point
HuggingFace detected a security incident on the Spaces platform and implemented token invalidation and enhanced security measures.
Details
The HuggingFace team recently detected unauthorized access related to Secrets on the Spaces platform. As a result, secrets for some Spaces may have been exposed.
Key actions taken:
- Immediately invalidated some HF tokens suspected of being exposed. (Affected users were notified by email.)
- Recommends that users refresh all keys and tokens, and encourages switching to fine-grained access tokens, which are now the new default.
Infrastructure security enhancements:
- Removed org tokens to improve tracking and auditing capabilities.
- Introduced a Key Management Service (KMS) for Spaces Secrets.
- Strengthened the system for identifying and proactively invalidating leaked tokens.
HuggingFace is currently conducting an investigation together with external cybersecurity experts, and has reported the matter to law enforcement and data protection authorities.
This summary was generated automatically by AI. Check the original for the author's claims and context. Copyright belongs to the original author.
Our guide explains how the AI works. Report summary errors, attribution issues, or removal requests via Contact.