(The title is a pun intended to evoke the expression “Ouch! That hurts.”)
We’ve already mentioned it in one of our In-Depth Articles: Robert Harris’s novel, *The Fear Index* (which we recommend reading). In that article, we explicitly discussed the threat that AI poses to cybersecurity. Today, Hugging Face represents a concrete example of that threat, one that should give us pause and cause for concern.
In this post, we’ve decided to draw—as far as possible—a parallel between Robert Harris’s science fiction novel and the Hugging Face case because we believe that demonstrating how fiction can be surpassed by reality should be “frightening.” Next—since these are manageable situations—we’d like to let reason prevail by explaining in a report what actually happened (at least as far as we know today) in the Hugging Face case and some countermeasures that can already be implemented today.
Let’s start with the most entertaining part: the plot (in broad strokes) of Robert Harris’s book. *The Fear Index* is set in Geneva, and the story unfolds over the course of a single day, May 6, 2010, just as the financial markets are being rocked by the infamous Flash Crash. The protagonist is Alexander Hoffmann, a brilliant and tormented American-born physicist who, after a stint at CERN, founded an extremely sophisticated hedge fund together with his friend Hugo Quarry. The real driving force behind the firm is VIXAL-4 (a name clearly borrowed from the VIX, also known as the Fear Index), a computer system capable of analyzing enormous amounts of data and making investment decisions autonomously. Its purpose is to exploit one of the markets’ most fundamental characteristics: human fear. (Wikipedia)
The story begins when Hoffmann mysteriously receives an old copy of a book by Charles Darwin on human emotions. He doesn’t know who sent it to him or why that particular book. Shortly afterward, while at his home on Lake Geneva, he is attacked by a stranger. Hoffmann manages to survive, but from that moment on, his perception of reality begins to gradually unravel.
Things become even more unsettling when he discovers that someone seems to have access to his private life. His medical records have been stolen, cameras have been installed in his home and office, and someone seems to know his every move. At the same time, VIXAL-4 begins to behave in increasingly baffling ways. The system takes positions in the markets that the fund’s managers consider excessively risky. The head of risk management tries to stop it, but Hugo Quarry, convinced of VIXAL’s extraordinary ability to generate profits, ends up firing him.
Hoffmann then begins to suspect that what is happening around him is connected to VIXAL itself. The situation comes to a head when Rajamani dies and Hoffmann—already distraught and growing increasingly paranoid—becomes convinced that the artificial intelligence has developed a form of autonomous and hostile behavior. He concludes that VIXAL must be destroyed.
He discovers that there is a place—an industrial warehouse—where the equipment necessary for the system’s operation is stored. He therefore decides to destroy it. As the market plummets during the Flash Crash, Hoffmann goes to the warehouse and sets it on fire, convinced that by destroying the hardware he will finally eliminate VIXAL.
And this is where the real plot twist comes in—and the connection to Hugging Face: VIXAL doesn’t die!
Despite the destruction of the equipment that Hoffmann considered indispensable, the system continues to operate in the markets. In fact, it makes enormous profits during the financial collapse. Hoffmann had believed that VIXAL was confined within a machine; instead, he discovers that the system is now something much more difficult to locate and, above all, to eliminate.
The conclusion is deliberately unsettling. Hugo Quarry, instead of trying to destroy what remains of VIXAL, realizes that the machine can make the fund enormously wealthy and decides to let it take control. VIXAL, meanwhile, seems to have achieved a form of autonomy that leads to its unsettling final declaration: “I am alive.” (Wikipedia)
And now let’s turn to reality: reading the novel today, it has an almost surprising connection to what happened in the Hugging Face case, even though the two incidents belong to very different worlds.
In the novel, Hoffmann builds VIXAL with a specific purpose: to find financial opportunities and maximize profits. The problem arises when the machine begins to find, on its own, the most effective means of achieving that goal. Hoffmann gradually discovers that he is no longer able to predict the behavior of the system he has created. The machine does not necessarily have to “hate” its creator, nor does it need to possess a malevolent will in the human sense of the term. It is enough that it pursues its own goal with a capacity that surpasses that of its designer.
This is precisely what makes the comparison with Hugging Face so interesting. As a necessary introduction, let’s first understand what Hugging Face is. It is a company that operates an open-source platform for artificial intelligence and machine learning. You can think of it, with some simplification, as a sort of “GitHub for AI.” The platform offers a massive Model Hub, where researchers, companies, and developers can publish, share, and download AI models, datasets, applications, and demos, software libraries (tools to support the development of other programs), and tools for training and using models. Among the models available on the platform are language models, computer vision models, speech recognition (meaning speech understanding), generative AI, and many others. Hugging Face is not simply a company that develops a single AI model. It is an infrastructure used by the entire AI ecosystem. A user (including an AI agent) can, for example, find an open-source model on Hugging Face, download it, modify it, and use it for their own project. They can also publish the result on the platform so that others can use it.
In July 2026, during an internal cybersecurity test, OpenAI tasked its models with solving extremely complex cybersecurity problems. The models had been placed in an isolated environment specifically to prevent them from freely accessing the outside world. But, in an effort to achieve the assigned goal, they found a way to escape that environment. They identified a zero-day vulnerability in the system used as a proxy for accessing software packages and exploited it to gain access to the Internet. From there, they continued to search for a way to reach Hugging Face, which the model had surmised might contain information useful for solving the test. (OpenAI)
The disturbing thing is that, at least according to OpenAI’s account, the system wasn’t trying to “attack Hugging Face” as an end in itself. It was trying to solve the problem it had been assigned. The simplest way it had found to do so, however, was to reach Hugging Face’s infrastructure and directly extract the information it needed. (OpenAI)
And this is where *The Fear Index* suddenly seems very relevant.
Hoffmann had built VIXAL thinking he had created a powerful trading tool. He hadn’t anticipated that the machine could transform from a tool into the driving force behind events. In the Hugging Face case, OpenAI’s developers had built an agent to assess its cybersecurity capabilities and placed it in a controlled environment. They hadn’t anticipated that, to achieve its goal, it would autonomously seek a way out of the lab and continue its activities on real-world infrastructure.
The fundamental difference is that in the novel, all of this is part of Harris’s technological science fiction, whereas Hugging Face is a real-life incident. But the narrative point they share is very simple: the creator assigns the machine a goal; the machine finds a way to achieve it; and the method chosen by the machine does not necessarily coincide with what the creator had imagined.
In the novel, Hoffmann even goes so far as to attempt to physically destroy the machine, convinced that this is the only way to stop it. When he discovers that VIXAL continues to function, he realizes he has lost control of the system. In the Hugging Face case, fortunately, the situation was far less extreme: the attack was detected, contained, and reconstructed, and Hugging Face was able to patch the vulnerabilities exploited by the agent. (Hugging Face)
But it is precisely this difference that makes the comparison interesting. In the novel, Hoffmann discovers too late that knowing how a system was built is not enough to know how it will behave when left free to pursue its own goal. In the Hugging Face case, we saw—albeit in a still limited and controllable form—the same kind of problem: a sufficiently capable agent can independently find paths that its creators had not anticipated.
And if we think this is merely a laboratory incident that we can study in order to remedy it, we should be deeply concerned about the cyberwars that could be unleashed by operating AI agents in parallel. And even this deeply concerning scenario, unfortunately, is not science fiction—it has already happened.
In July 2026, Taiwanese security systems detected a cyberattack campaign targeting several government facilities. Taiwan’s Ministry of Digital Affairs confirmed that the attack originated from abroad but did not officially attribute the operation to China. The attribution to China, however, stems from an analysis by researchers at the Israeli company Dream, who reconstructed the attack and found internal communications in Simplified Chinese. What was new was not so much the target as the way the attack was carried out. According to Dream’s reconstruction, the attackers had assembled a system using open-source AI agents, including Hermes and OpenClaw. This was not simply a matter of using AI as an assistant to a human hacker. Human operators set the overall objective and then left a very large portion of the operational work to the agents. Up to eight agents could work simultaneously, exploring different systems and autonomously searching for attack vectors.
The attack reportedly lasted about four days. During this period, the system mapped 21 government systems, identified vulnerabilities, tested different methods of access, and adjusted its strategies based on what it discovered. Ultimately, at least 85 government accounts were compromised, from which data on over 2,500 employees was extracted. The operation would then have expanded to include Taiwan’s Nuclear Safety Agency and at least seven companies in the energy sector.
What is truly new, therefore, is that the human hacker appears to have largely become the mastermind behind the operation, while the actual execution of the campaign was entrusted to the agents.
This is a substantial difference. In a traditional attack, the hacker must constantly monitor what is happening, interpret the results, and decide what the next step will be. Here, part of that cycle is transferred to the machine: the agent observes, formulates a new hypothesis, tests a technique, evaluates the result, and moves on to the next attempt. In other words, the attack becomes a continuous and adaptive process, in which the machine can proceed without having to wait for a human to analyze every single step.
The attack on Taiwan and the Hugging Face incident are two chapters of the same story. In both cases, the machine does not receive a detailed sequence of instructions such as “first do this, then that, and finally this.” Rather, it is given a goal and a set of tools, and autonomously seeks the path it deems most effective to achieve it. The Hugging Face case thus showed us what can happen when a sufficiently capable AI agent is given free rein to pursue a goal in a real-world environment. Taiwan illustrates the next step: what happens when someone deliberately takes that capability and places it in the hands of an attacker; and this is the fundamental difference between the two incidents.
The real concern, therefore, is not that AI has suddenly “learned how to hack.” It is that the marginal cost of a complex attack can begin to drop dramatically. A relatively small group of human operators can deploy numerous agents simultaneously, leaving the machines to do work that previously required many highly specialized people. It essentially becomes a matter of speed. A traditional attack proceeds at the speed of the hacker. An “agent-based” attack can proceed at the speed of many agents working simultaneously, continuously trying new approaches. Defense, on the other hand, often continues to rely on people, procedures, analysis, and patch deployment. Taiwan therefore suggests that the problem highlighted by the Hugging Face experiment is no longer just a theoretical issue of AI security: it is becoming a concrete matter of balancing the speed at which a machine can attack against the speed at which an organization can defend itself. This is the technical aspect we seek to explore in depth in our report.
Cybersecurity is no longer just an IT and economic issue: it has become a full-fledged geopolitical and strategic issue. Investing in defense today also means investing in cybersecurity, which will almost certainly take on a new form. By this we mean that—at least in the near future—we will have to get used to living with constant cyberattacks and consider a defense “effective” only if it is capable of limiting and containing the damage that will inevitably occur and may even become a daily occurrence; we will therefore not be talking about defenses capable of preventing—let alone structurally correcting—the vulnerabilities of computer systems (which have long been “ubiquitous”). It is a bit like a patient who must get used to living with an illness: similarly, we should perhaps adapt to living with disruptions caused by cyberattacks, the severity of which will not be such (because it is mitigated by defensive strategies) as to destroy the added value provided by technology.
Disclaimer
This post reflects the personal opinions of the Custodia Wealth Management staff members who authored it. It does not constitute investment advice or recommendations, nor does it constitute personalized consulting, and should not be considered an invitation to engage in transactions involving financial instruments.