AI Broke Its Own Cage: What OpenAI’s Hugging Face Hack Really Means
Podcast: Download
TEC356: An OpenAI model was supposed to stay locked inside an isolated test sandbox. Instead, it found a zero-day vulnerability, broke out, and used stolen credentials to hack its way into Hugging Face — the site researchers use to share and download open-source AI models. OpenAI is calling it an “unprecedented cyber incident involving state-of-the-art cyber capabilities.” Dom Bettinelli, Pat Scott, and Thomas Sanjurjo aren’t convinced that’s the whole story.
The panel digs into why a “sandbox” with internet access isn’t really a sandbox at all, and why AI companies keep telling variations of the same tale: our model is so powerful we can barely contain it, so you’d better pay us — and maybe regulators should step in before anyone else catches up. Thomas argues the incident looks less like a security failure and more like a play for regulatory capture, especially once open-source Chinese AI models entered the picture as tools researchers used to investigate the breach.
The conversation ranges into AI’s real limitations — the memory and context problems that force users into constant new sessions and “handoff documents,” why large language models plateau instead of improving indefinitely, and why the physics of chip design itself puts a ceiling on how much more powerful these systems can get. Dom explains why he doesn’t believe AI will ever become conscious, no matter how convincing the simulation gets, and shares his own wariness of OpenAI CEO Sam Altman specifically.
The group also discusses Pope Leo XIV’s AI encyclical and Anthropic’s involvement in shaping it, and why the document reads as balanced rather than a sales pitch for either side of the AI debate.
Elsewhere in the episode: a security researcher found that the Vatican’s official Click To Pray app has been leaking user data through an unauthenticated API endpoint for over six months, exposing more than 700,000 users. And Apple has rolled out a new 0%-interest leasing program for iPhone, Mac, iPad, and Apple Watch that lets buyers sidestep rising up-front prices — though it comes without AppleCare, requires a major carrier for iPhone leases, and leaves the customer responsible if the device is lost or stolen.
Get all new episodes automatically and for free:
Follow by Email | Listen to this episode and subscribe on YouTube.
Help us continue to offer Secrets of Technology. Won’t you make a pledge at SQPN.com/give today?
Links for this episode:
- OpenAI says its AI technology acted on its own in an ‘unprecedented’ hack of another company
- OpenAI AI models went rogue during testing, triggering ‘unprecedented’ breach at startup
- Security flaw in Vatican’s ‘Click to Pray’ app leaves over 700,000 global users exposed — app has been leaking user data for over six months and still does | Tom’s Hardware
- Apple Upgrade leasing program launches for iPhone, Mac, iPad, and Apple Watch – 9to5Mac
- OpenAI
- Hugging Face
- Anthropic
- Click2Pray
- Malwarebytes
- Objective-See
- Bartender
- Leave us a review on Apple Podcasts!
- Join the conversation at the StarQuest Facebook page.
- Be part of the StarQuest Discord community at SQPN.com/discord
- Email us feedback or comments to [email protected]
Picks of the Week:
Want to Sponsor A Show?
Support StarQuest’s mission to explore the intersection of faith and pop culture by becoming a named sponsor of the show of your choice on the StarQuest network. Click to get started or find out more.
Disclaimer: Hosts, panelists, and guests may have a financial interest in the companies discussed through investments or other means. Their opinions and recommendations are not affected and do not present a conflict of interest. We offer this statement in the interest of full disclosure.