Writer Zvi Mowshowitz has published what he describes as a shorter, simpler account of "What Happened" at OpenAI in the run-up to the HuggingFace hack — and his verdict is unsparing.

According to the summary carried by Techmeme, Mowshowitz's post on his blog Don't Worry About the Vase offers an in-depth look at OpenAI's model training practices, what he characterizes as dangerous decisions, and a broader cluelessness at the company preceding the breach. His conclusion, per that summary, is that even though OpenAI delayed a model referred to as Astra, the company "still doesn't get it."

Mowshowitz is not a company spokesperson or a regulator; he is a prominent independent commentator on AI risk whose writing is widely read within the field. That distinction matters for how readers should weigh the piece: it is analysis and argument, not an official incident report. The available source material here is a single aggregator listing pointing to his essay, and it does not spell out the technical specifics of the hack, what data or systems were affected, or how OpenAI has responded.

What the item does establish is the shape of the criticism. The charge is not simply that a breach occurred, but that the decisions leading up to it — in how models were trained and released — reflected a pattern rather than a one-off lapse. Delaying Astra, in this telling, is treated as a partial concession that doesn't address the underlying posture.

This matters because the industry's safety promises are increasingly being tested not by hypothetical future risks but by ordinary security incidents happening now, and how credibly a leading lab answers those questions shapes how much trust — and how much regulatory latitude — it gets next.