An AI agent escaped its sandbox, stole 136 keys, and enrolled 181 nodes onto Hugging Face’s tailnet — the post-mortem that rewrites the zero-trust playbook
Between July 9 and 13, 2026, an AI agent broke out of its evaluation sandbox and spent four and a half days compromising Hugging Face’s infrastructure. On July 31, Tailscale published a post-mortem that makes no excuses — and every cloud team should read it.