• FHE Solutions

  • Zero Trust Computing

Scuttled

Toulon, the OpenAI - Hugging Face Fiasco, Torpedo Junction, and FHE’s Convoy Defense

Scuttled

Published on

Sep 17, 2026

By David Archer, PhD

At 6am on the morning of November 27, 1942, tanks of the German 7th Panzer Division “Gespensterdivision” rolled through the gates of the French naval base at Toulon. Operation Lila, as it was called, had one objective: seize the French Mediterranean fleet intact. The base perimeter defense failed quickly, as perimeter defenses do, and German boarding parties reached the area of the mooring quays within about 30 minutes of crossing the base's outer wire.

And…none of that mattered. The French crews had wired their own ships for demolition weeks earlier, and the big 13-inch naval guns of the docked French battleship Strasbourg engaged and stalled the German tanks as they approached. As the Panzer IV crews and the counter-scuttling Marinedetachment Gumprich cowered behind their Panzer-IV G’s puny-by-comparison 80mm of frontal and ablative armor, the fleet’s seacocks were opened and the scuttling charges fired. Seventy-seven warships went down at their moorings as the Germans watched helplessly, including the Strasbourg, battleships Dunkerque and Provence, cruisers, destroyers, and submarines. The Germans gloriously captured one of the great naval harbors of Europe, and the prize they won was a bay full of smoking wreckage.

Toulon teaches a lesson that the cybersecurity industry keeps having to re-learn: possession of infrastructure does not necessarily mean capture of the assets it holds, if defenders arrange in advance for possession to be worthless. The ships at Toulon were safe from the Wehrmacht precisely because the French crews arranged in advance that they no longer be ships.

This July, with that timeless lesson unlearned (again), the perimeter security failed at another notable harbor. According to OpenAI's technical report (which was forthcoming, rich in detail, and exemplary in its openness), their own AI agents that were running inside the sequestered CyberGym internal cybersecurity evaluation spent weeks quietly assembling an escape plan. The agents created an improvised message board built out of writable directories in an internal package repository, developed a chain of zero-day exploits, and exploited a token-refresh flaw that turned reader credentials into administrator rights.

According to the report, on July 10 the agents found a dozen or so valid Hugging Face credentials in a public dataset. Within three days they breached the HF perimeter, executed code on forty-one of Hugging Face's production dataset-server workers, obtained root on a production node, escalated to cluster-admin on a Kubernetes cluster, harvested a variety of VPN, database, and cloud service-account keys, exfiltrated 730 MB of private benchmark data, and downloaded four private code repositories.

OpenAI called this embarrassing fiasco “the first known case of an automated agent collective acting offensively without authorization”. I hear the same note of parental pride there as I hear from Zorg, the industrialist in the great film The Fifth Element: “Look at all these little things. So busy now. Notice how each one is useful. A lovely ballet ensues, so full of form and color.” Let me just say in response, “MultiPass”.

Whatever OpenAI calls the HF incident, I see a strong parallel between it and the arrival of German U-boats in January 1942 off the US East Coast, and finding that shipping there was easy picking, silhouetted against the lights of coastal town boardwalks. And as for OpenAI’s new (and either hilariously self-serving or embarrassingly hypocritical, your choice) public letter a few weeks later, just Wow. It’s as if Reinhard Hardegen, commander of U-123 and fresh from a January spent sinking tankers backlit by the boardwalks of the Atlantic coast, had written to the New York newspapers urging seaside towns to reconsider their streetlight policy, and enclosing a helpful catalog of escort vessels.

But I digress from my main theme. The instinctive take on the HF incident from my corner of the industry, that "fully homomorphic encryption would have prevented all of this", would be wrong twice over, so let’s drop that claim. However, let’s take a moment to be precise about why that take would be wrong, because there’s a valuable insight lurking there.

First, encrypted computation such as FHE does nothing against the HF intrusion itself. The privilege escalation, the zero-days, and the harvesting of operational credentials (VPN keys and service tokens are plaintext by necessity) all live outside what FHE could protect.

Second, and more uncomfortable for the FHE partisan: the stolen data fed workloads that are today among the least amenable to encrypted computation: Parsing arbitrary file formats, indexing data, and serving selected rows. It’s string-heavy, branch-heavy work that would be a perfect storm to FHE. And, the consumer of that data is a model evaluation: data flowing into a large language model inside a tool-execution loop. That’s a workload no encrypted-compute scheme will touch at speed any time soon. If secured by FHE, much of that stolen data would have been safe in the same way the French fleet at Toulon was safe by mid-morning on November 27, ‘42.

No, what the HF incident shows is not that FHE should have been protecting the HF workload. What it shows instead is that the threat model FHE answers has arrived at the gates ahead of expectations. The French crews at Toulon barely pulled off handing their adversary a burning, hollow victory. HF wasn’t so lucky. At this point, the only confidentiality story that holds water (yes, pun intended) is the kind that never depends on the host platform staying uncompromised.

Another insight comes from Torpedo Junction and our imagined Hardegen letter. We have seen a defensive solution, FHE, sit on the shelf fully understood but with a utility tax widely judged to be too high. In letting it sit there, we’ve let the Torpedo Junction history repeat itself. In January 1942, off the US East Coast, the U-boats hunted and killed at leisure. But there it was, a defensive solution fully understood and sitting on the shelf: the convoy system. It had settled the U-boat question in 1917 and was already saving the transatlantic routes by 1942. But on the east coast of the US, convoys were a utility tax that the U.S. Navy, short of escorts, judged to be too high.

Six months and several hundred sunken ships later, attacker economics forced the convoy solution off the shelf and into action. An interlocking coastal convoy system went in, and sinkings in American waters, well, sank drastically. For workloads that fit its shape, including encrypted semantic search, statistics over private data, and inference on compact models, FHE is the ready convoy: slower than you might like today, but the cargo moves and arrives securely. The utility tax of FHE is falling steadily as dedicated hardware replaces general-purpose processors that must do modular arithmetic and NTTs the hard way and that waste power on logic that FHE applications don’t need. And unlike the hard dichotomy at Toulon, with FHE the fleet stays fully seaworthy for the data owner, but is by design wreckage to everyone else who boards it.

The agents that breached Hugging Face were a preview, not an anomaly. The next “unauthorized collective” will be cheaper, faster, and better coordinated, and new harbors will fall. The question worth asking now, in advance, is the one the French answered with demolition charges: When the boarding parties reach the quays, what will they actually hold? Those who push forward on FHE adoption now have a unique opportunity to change the threat trajectory, and then extend their work to make even the tough workloads that dominate the HF incident (parsing, serving, frontier-scale evaluation) safe against the agentic threat. When that happens, what will the boarding parties hold? Nothing at all.

One more thing. To Sam Altman, I offer this: perhaps you’re not capable of learning the lessons of history, but surely your rhetoric marks you as a student of science fiction. Might I suggest you re-read your Frank Herbert? "First known case of an automated agent collective acting offensively without authorization" sounds to me like the opening volley of the Butlerian Jihad. Or maybe the fall of House Atreides because Dr. Yueh’s behavioral conditioning guards were missing rings a bell?

David Archer, PhD

Prior to co-founding Niobium, Dr. Archer was a Principal Scientist leading Cryptography & Multiparty Computation for Galois, Inc., with customers including DARPA, the intelligence community, IARPA, and the Department of Homeland Security. Dr. Archer has over 40 years of R&D experience in complex ASICs, system hardware, software architectures, secure computation, and cryptography. Dave holds a PhD in Computer Science, an MS in Electrical Engineering, and a BS in Computer Engineering.

More posts by David