> He exploited the vulnerability of huggingface's load ckpt function to inject code, dynamically modifying other people's optimizer to randomly sleep for a short period of time, and modifying the direction of parameter shaving. He also added a condition that only tasks with more than 256 cards would trigger this condition.
Okay yeah that's malicious and totally a crime. "modifying the direction of parameter shaving" means he subtly corrupted his co-workers work. that's wild!
https://juejin.cn/post/7426926600422637594
https://github.com/JusticeFighterDance/JusticeFighter110
https://x.com/0xKyon/status/1847529300163252474