The a16z Show · Friday, August 7, 2026
A partnership aimed at cleaning up credentials exposed in training sets revealed approximately a quarter million live API keys within datasets hosted on Hugging Face. alarmingly, one of these keys granted direct push access to a foundational Linux library, posing a risk of distributing malware to a significant portion of global machines. This highlights the critical need for better credential management in AI training data.
“What was interesting is we were in the middle of partnering with Hugging Face to clean up all of the credentials that had been exposed through all of their training sets, not Hugging Face's training, but people who hosted training sets on Hugging Face.”
“Turned out there were about a quarter million live keys in their training sets, many of which had direct supply chain implications.”
“There was a foundational Linux library, and one of the keys that had direct push access to it. It could have pushed malware to most machines on the planet.”