← Front page

The a16z Show · Friday, August 7, 2026

Hugging Face Training Sets Contained Quarter Million Live Keys, Including Critical Linux Library Access

A partnership aimed at cleaning up credentials exposed in training sets revealed approximately a quarter million live API keys within datasets hosted on Hugging Face. alarmingly, one of these keys granted direct push access to a foundational Linux library, posing a risk of distributing malware to a significant portion of global machines. This highlights the critical need for better credential management in AI training data.

companyHugging Face

The tape

3 quotes
What was interesting is we were in the middle of partnering with Hugging Face to clean up all of the credentials that had been exposed through all of their training sets, not Hugging Face's training, but people who hosted training sets on Hugging Face.
Turned out there were about a quarter million live keys in their training sets, many of which had direct supply chain implications.
There was a foundational Linux library, and one of the keys that had direct push access to it. It could have pushed malware to most machines on the planet.
Heard on The a16z Show — “The Reality of AI-Powered Cyberattacks | Truffle Security & Socket, published Friday, August 7, 2026. Heardvine summarizes and quotes with attribution and timestamps, and links to the original everywhere.
Transcribed via Gemini audio transcription · $0.02