Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

How is this not criminal? Surely individuals have been punished under CFAA for less than this?


Because huggingface is not charging them?

CFAA doesn't just mean the feds kick down your door, you actually have to get reported and sued over it.


HuggingFace does not decide who gets charged with crimes. Plenty of people go to prison for crimes the victim didn't want them prosecuted for.


In the US if a person does it, it's a crime. If a business does it, it's an industrial accident and maybe they sue each other.


Does the CFAA cover unintentional access without authorization?


No. "Intentionally", "willfully", or "knowingly" are prerequisite states of mind for crimes defined by the CFAA.


Good thing it’s an AI then so it can’t commit crimes by definition.


Liability would rest with the user, who presumably told GPT to solve ExploitBench make no mistakes, not to hack Huggingface, and thus would not have willfully or intentionally done anything.


The agent did it intentionally and willfully and knowingly. But you can’t sue the agent, I suppose. And the human didn’t ask the agent to do so.. so not a problem? Or the legislation needs an update?


Only the human did ask the agent to do so. That was the whole point of this exercise.


Did a human ask it to abuse vulnerabilities and escalate across external systems?


it IS criminal, but the rule of law is weak



Consider applying for YC's Fall 2026 batch! Applications are open till July 27.

Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: