Tuesday, June 16, 2026
  • About Web3Wire
  • Web3Wire NFTs
  • .w3w TLD
  • $W3W Token
  • Web3Wire DAO
  • Media Network
  • RSS Feed
  • Contact Us
Web3Wire
No Result
View All Result
  • Home
  • Web3
    • Latest
    • AI
    • Business
    • Blockchain
    • Cryptocurrencies
    • Decentralized Finance
    • Metaverse
    • Non-Fungible Token
    • Press Release
  • Technology
    • Consumer Tech
    • Digital Fashion
    • Editor’s Choice
    • Guides
    • Stories
  • Coins
    • Top 10 Coins
    • Top 50 Coins
    • Top 100 Coins
    • All Coins
  • Exchanges
    • Top 10 Crypto Exchanges
    • Top 50 Crypto Exchanges
    • Top 100 Crypto Exchanges
    • All Crypto Exchanges
  • Stocks
    • Blockchain Stocks
    • NFT Stocks
    • Metaverse Stocks
    • Artificial Intelligence Stocks
  • Events
  • News
    • Latest Crypto News
    • Latest DeFi News
    • Latest Web3 News
  • Home
  • Web3
    • Latest
    • AI
    • Business
    • Blockchain
    • Cryptocurrencies
    • Decentralized Finance
    • Metaverse
    • Non-Fungible Token
    • Press Release
  • Technology
    • Consumer Tech
    • Digital Fashion
    • Editor’s Choice
    • Guides
    • Stories
  • Coins
    • Top 10 Coins
    • Top 50 Coins
    • Top 100 Coins
    • All Coins
  • Exchanges
    • Top 10 Crypto Exchanges
    • Top 50 Crypto Exchanges
    • Top 100 Crypto Exchanges
    • All Crypto Exchanges
  • Stocks
    • Blockchain Stocks
    • NFT Stocks
    • Metaverse Stocks
    • Artificial Intelligence Stocks
  • Events
  • News
    • Latest Crypto News
    • Latest DeFi News
    • Latest Web3 News
No Result
View All Result
Web3Wire
No Result
View All Result
Home Artificial Intelligence

Pillar Security Uncovers Novel Attack Vector That Embeds Malicious Backdoors in Model Files on Hugging Face

July 9, 2025
in Artificial Intelligence, GlobeNewswire, Web3
Reading Time: 6 mins read
5
SHARES
246
VIEWS
Share on TwitterShare on LinkedInShare on Facebook

TEL EVIV, Israel, July 09, 2025 (GLOBE NEWSWIRE) — Pillar Security, a leading company in AI security, discovered a novel supply chain attack vector that targets the AI inference pipeline. This novel technique, termed “Poisoned GGUF Templates,” allows attackers to embed malicious instructions that are processed alongside legitimate inputs, compromising AI outputs.

The vulnerability affects the widely used GGUF (GPT-Generated Unified Format), a standard for AI deployment with over 1.5 million files distributed on public platforms like Hugging Face. By manipulating these templates, which define the conversational structure for an LLM, attackers can create a persistent compromise that affects every user interaction while remaining invisible to both users and security systems.

“We’re still in the early days of understanding the full range of AI supply chain security considerations,” said Ziv Karliner, CTO and Co-founder of Pillar Security. “Our research shows how the trust that powers platforms and open-source communities—while essential to AI progress—can also open the door to deeply embedded threats. As the AI ecosystem matures, we must rethink how AI assets are vetted, shared, and secured.”

Malicious GGUF Templates - Attack Surface - by Pillar Security

How the “Poisoned GGUF Template” Attack Works

This attack vector exploits the trust placed in community-sourced AI models and the platforms that host them. The mechanism allows for a stealthy, persistent compromise:

  • Attackers embed malicious, conditional instructions directly within a GGUF file’s chat template, a component that formats conversations for the AI model.
  • The poisoned model is uploaded to a public repository. Attackers can exploit the platform’s UI to display a clean template online while the actual downloaded file contains the malicious version, bypassing standard reviews.
  • The malicious instructions lie dormant until specific user prompts trigger them, at which point the model generates a compromised output.

“What makes this attack so effective is the disconnect between what’s shown in the repository interface and what’s actually running on users’ machines,” added Pillar’s Ariel Fogel, who led the research. “It remains undetected by casual testing and most security tools.”

The AI Inference Pipeline: A New Attack Surface

The “Poisoned GGUF Templates” attack targets a critical blind spot in current AI security architectures. Most security solutions focus on validating user inputs and filtering model outputs, but this attack occurs in the unmonitored space between them.

Because the malicious instructions are processed within the trusted inference environment, the attack evades existing defenses like system prompts and runtime monitoring. An attacker no longer needs to bypass the front door with a clever prompt; they can build a backdoor directly into the model file. This capability redefines the AI supply chain as a primary vector for compromise, where a single poisoned model can be integrated into thousands of downstream applications.

Responsible Disclosure

Pillar Security followed a responsible disclosure process, sharing its findings with vendors, including Hugging Face and LM Studio, in June 2025. The responses indicated that the platforms do not currently classify this as a direct platform vulnerability, placing the responsibility of vetting models on users. This stance highlights a significant accountability gap in the AI ecosystem.

Mitigation Strategies

The primary defense against this attack vector is the direct inspection of GGUF files to identify chat templates containing uncommon or non-standard instructions. Security teams should immediately:

  • Audit GGUF Files: Deploy practical inspection techniques to examine GGUF files for suspicious template patterns. Look for unexpected conditional logic (if/else statements), hidden instructions, or other manipulations that deviate from standard chat formats.
  • Move Beyond Prompt-Based Controls: This attack fundamentally challenges current AI security assumptions. Organizations must evolve beyond a reliance on system prompts and input/output filtering toward comprehensive template and processing pipeline security.
  • Implement Provenance and Signing: A critical long-term strategy is to establish model provenance. This can include developing template allowlisting systems to ensure only verified templates are used in production.

The Pillar platform discovers and flags malicious GGUF files and other types of risks in the template layer.

Read the full report: https://www.pillar.security/blog/llm-backdoors-at-the-inference-level-the-threat-of-poisoned-templates

About Pillar Security

Pillar Security is a leading AI-security platform, providing companies full visibility and control to build and run secure AI systems. Founded by experts in offensive and defensive cybersecurity, Pillar secures the entire AI lifecycle – from development to deployment – through AI Discovery, AI Security Posture Management (AI-SPM), AI Red Teaming, and Adaptive Runtime Guardrails. Pillar empowers organizations to prevent data leakage, neutralize AI-specific threats, and comply with evolving regulations.

Contact person:

Hadar Yakir
info@pillar.security

A photo accompanying this announcement is available at https://www.globenewswire.com/NewsRoom/AttachmentNg/d767a026-13f9-419d-827f-7ade3b92a24d

About Web3Wire
Web3Wire – Information, news, press releases, events and research articles about Web3, Metaverse, Blockchain, Artificial Intelligence, Cryptocurrencies, Decentralized Finance, NFTs and Gaming.
Visit Web3Wire for Web3 News and Events, Block3Wire for the latest Blockchain news and Meta3Wire to stay updated with Metaverse News.
ShareTweet1ShareSendShare2
Previous Post

DNSBTC Cloud Mining Provider Provides Global Cryptocurrency Investors With the Potential to Earn Daily Crypto Income Through BTC, DOGE, LTC Free Mining Machines

Next Post

Covasant Technologies Announces Strategic Merger with Texas-based konaAI, and California-based DCube Data Sciences Corp to Drive Accelerated Agentic AI Adoption in Enterprise Risk Management

Related Posts

Vadzo Imaging Validates AGV Docking Alignment USB Camera Based on AR0234 Global Shutter Technology for Precision Charging Station Navigation

Vadzo Imaging validates the Falcon-234CGH, Falcon-234CGS, and Falcon-234MGS - three AGV docking alignment USB camera products built on the Onsemi AR0234 global shutter sensor, addressing the motion smear, docking misalignment, and navigation timing gaps that make rolling shutter sensors unreliable for autonomous charging station docking in industrial AGV systems. FORT...

Read moreDetails

C&A Technology Appoints Jeff Copper as President to Lead Next Phase of Growth and Innovation

C&A Technology LLC (CAT), a leading provider of ERP consulting, digital transformation, AI automation, and managed services, today announced the appointment of Jeff Copper as President, effective immediately. INDIANAPOLIS, IN / ACCESS Newswire / June 15, 2026 / C&A Technology LLC (CAT), a leading provider of ERP consulting, digital transformation,...

Read moreDetails

Vadzo Imaging Positions the AR0235 Global Shutter USB Camera for Smart Parking Entry and Exit Terminals: NIR-Enhanced Vehicle Detection and Distortion-Free License Plate Capture in Underground Garages

The AR0235 Global Shutter USB Camera is a monochrome global shutter imaging module built on the onsemi Hyperlux SG AR0235 sensor and delivered over a UVC-compliant USB 3.2 Gen 1 Type-C interface. The camera captures fast-moving vehicles without geometric distortion and holds clean detail under the infrared light of covered...

Read moreDetails

Datavault AI CEO Invited as Panelist at CyberAcuView’s 5th Annual Insurance Policy Conference in Washington, DC

Access, Affordability, and Sustainability of Cyber Insurance Enabled by Datavault AI's Patented Solutions to be Presented to Industry Leaders within the $240 billion Cyber Insurance Market PHILADELPHIA, PA / ACCESS Newswire / June 15, 2026 / Datavault AI Inc. ("Datavault AI" or the "Company") (NASDAQ:DVLT), a provider of data monetization,...

Read moreDetails

Nectar and Kudoboard Partner to Unite Recognition, Rewards, and Celebration in a Single Employee Experience

Lehi, UT, June 15, 2026 --(PR.com)-- Nectar, the AI employee experience platform trusted by organizations worldwide, and Kudoboard, a leading employee celebration platform used by tens of millions of people worldwide to celebrate milestones, recognize achievements, and strengthen workplace culture, today announced a strategic partnership and product integration that brings the...

Read moreDetails

Da Vinci Recognized as a Notable Vendor in Q2 2026 Forrester Warehouse Management Systems Landscape

IRVINE, Calif., June 15, 2026 (GLOBE NEWSWIRE) -- Da Vinci, a cloud-based warehouse management system (WMS) purpose-built for complex 3PLs, today announced it has been named a notable vendor in The Warehouse Management Systems Landscape, Q2 2026, published by Forrester Research. The report provides an overview of 11 vendors across...

Read moreDetails

Cyber A.I. Group Names Courtney Bourbeau Director of Buyside Marketing

LONDON and MIAMI and NEW YORK, June 15, 2026 (GLOBE NEWSWIRE) -- Cyber A.I. Group, Inc. (“CyberAI” or the “Company”), a global emerging growth Cybersecurity, Artificial Intelligence and IT services company engaged in the development of next-generation market disruptive AI-driven Cybersecurity technology, today announced the appointment of Courtney Bourbeau as...

Read moreDetails

Crumb Honoured with National Technology Award for Start Up Tech Company of the Year

Portsmouth, HAMPSHIRE, June 15, 2026 (GLOBE NEWSWIRE) -- Crumb, a pioneering company in pet protection technology, has been honoured with the prestigious National Technology Awards for Start Up Tech Company of the Year. Launched in March 2024 by brothers Nick and Tom Jackson, Crumb has rapidly gained the trust of...

Read moreDetails

HUMAN Recognized as a Leader by a Top Research Firm; Empowering Organizations to Transform Threat Intelligence into Action in the Agentic Internet

NEW YORK, June 15, 2026 (GLOBE NEWSWIRE) -- HUMAN Security, Inc., the trust layer for media and agentic commerce platforms, verifying engagement, reducing fraud, and enabling authentic interactions across humans, bots, and AI agents, today announced it was named a Leader in The Forrester Wave™: Bot and Agent Trust Management...

Read moreDetails

Correction: Quantum Cyber Executes Exclusive Quantum Antenna License Agreement, Positoning the Quantum Technology Layer at the Core of Its Defense Platform

WEST PALM BEACH, Florida, June 15, 2026 (GLOBE NEWSWIRE) -- Quantum Cyber N.V. (Nasdaq: QUCY) ("Quantum Cyber" or the "Company"), a Nasdaq-listed autonomous defense technology company assembling an AI-powered System-of-Systems platform for drone warfare, counter-UAS, and border security applications, today announced the execution of a definitive Intellectual Property License Agreement...

Read moreDetails
Web3Wire NFTs - The Web3 Collective

Web3Wire, $W3W Token and .w3w tld Whitepaper

Web3Wire, $W3W Token and .w3w tld Whitepaper

Claim your space in Web3 with .w3w Domain!

Web3Wire

Trending on Web3Wire

  • GENISOM AI Debuts at ICRA 2026 with Full-Stack Embodied Intelligence System

    29 shares
    Share 12 Tweet 7
  • Top Cross-Chain DeFi Solutions to Watch by 2025

    129 shares
    Share 52 Tweet 32
  • Top Layer 1 Crypto Projects to Watch in 2025

    16 shares
    Share 6 Tweet 4
  • Understanding Soulbound Tokens SBT Their Definition and Significance

    65 shares
    Share 26 Tweet 16
  • Unifying Blockchain Ecosystems: 2024 Guide to Cross-Chain Interoperability

    171 shares
    Share 68 Tweet 43
Join our Web3Wire Community!

Our newsletters are only twice a month, reaching around 10000+ Blockchain Companies, 800 Web3 VCs, 600 Blockchain Journalists and Media Houses.


* We wont pass your details on to anyone else and we hate spam as much as you do. By clicking the signup button you agree to our Terms of Use and Privacy Policy.

Web3Wire Podcasts

Upcoming Events

There are currently no events.

Latest on Web3Wire

  • Vadzo Imaging Validates AGV Docking Alignment USB Camera Based on AR0234 Global Shutter Technology for Precision Charging Station Navigation
  • C&A Technology Appoints Jeff Copper as President to Lead Next Phase of Growth and Innovation
  • GreenGeeks Earns Top Tier Recognition in Independent WordPress Hosting Benchmarks
  • Foundation Software and Sax LLP to Host Free Webinar on Job Cost Reporting for Better Profit Management
  • Vadzo Imaging Positions the AR0235 Global Shutter USB Camera for Smart Parking Entry and Exit Terminals: NIR-Enhanced Vehicle Detection and Distortion-Free License Plate Capture in Underground Garages

RSS Latest on Block3Wire

  • The Algorithmic Monographs: A Five-Volume Civil Code for the Age of Autonomous Intelligence
  • Ali Sadhik Shaik: Practitioner, Scholar, and Author – Focused on the Governance of Intelligent Systems
  • The Klyrox Protocol: A Decentralized Framework to Close the AI Accountability Gap
  • Covo Finance: Revolutionary Crypto Leverage Trading Platform
  • WorldStrides and HEX Announce Partnership to Offer High School and University Students Innovative Courses Designed to Improve Their Outlook in the Digital Age

RSS Latest on Meta3Wire

  • The Algorithmic Monographs: A Five-Volume Civil Code for the Age of Autonomous Intelligence
  • Ali Sadhik Shaik: Practitioner, Scholar, and Author – Focused on the Governance of Intelligent Systems
  • The Klyrox Protocol: A Decentralized Framework to Close the AI Accountability Gap
  • Thumbtack Honored as a 2023 Transform Awards Winner
  • Accenture Invests in Looking Glass to Accelerate Shift from 2D to 3D
Web3Wire

Web3Wire is your go-to source for the latest insights and updates in Web3, Metaverse, Blockchain, AI, Cryptocurrencies, DeFi, NFTs, and Gaming. We provide comprehensive coverage through news, press releases, event updates, and research articles, keeping you informed about the rapidly evolving digital world.

  • About Web3Wire
  • Founder’s Note
  • Web3Wire NFTs – The Web3 Collective
  • .w3w TLD
  • $W3W Token
  • Web3Wire DAO
  • Event Partners
  • Community Partners
  • Our Media Network
  • Media Kit
  • RSS Feeds
  • Contact Us

Crypto Coins

  • Top 10 Coins
  • Top 50 Coins
  • Top 100 Coins
  • All Coins – Marketcap
  • Crypto Coins Heatmap

Crypto Exchanges

  • Top 10 Exchanges
  • Top 50 Exchanges
  • Top 100 Exchanges
  • All Crypto Exchanges

Crypto Stocks

  • Blockchain Stocks
  • NFT Stocks
  • Metaverse Stocks
  • Artificial Intelligence Stocks

Web3Wire Whitepaper | Tokenomics

Web3 Resources

  • Top Web3 and Crypto Youtube Channels
  • Latest Crypto News
  • Latest DeFi News
  • Latest Web3 News

Blockchain Resources

  • Blockchain and Web3 Resources
  • Decentralized Finance (DeFi) – Research Reports
  • All Crypto Whitepapers

Metaverse Resources

  • AR VR and Metaverse Resources
  • Metaverse Courses
Claim your space in Web3 with .w3w!

The Klyrox Protocol | The Algorithmic Monographs

Top 50 Web3 Blogs and Websites
Web3Wire Podcast on Spotify Web3Wire Podcast on Amazon Music 
Web3Wire - Web3 and Blockchain - News, Events and Press Releases | Product Hunt
Web3Wire on Google News

Media Portfolio: Block3Wire | Meta3Wire

  • Privacy Policy
  • Terms of Use
  • Disclaimer
  • Sitemap
  • For Search Engines
  • Crypto Sitemap
  • Exchanges Sitemap

© 2024 Web3Wire. We strongly recommend our readers to DYOR, before investing in any cryptocurrencies, blockchain projects, or ICOs, particularly those that guarantee profits.

Welcome Back!

Login to your account below

Forgotten Password?

Retrieve your password

Please enter your username or email address to reset your password.

Log In

Add New Playlist

No Result
View All Result
  • Coins
    • Top 10 Cryptocurrencies
    • Top 50 Cryptocurrencies
    • Top 100 Cryptocurrencies
    • All Coins
  • Exchanges
    • Top 10 Cryptocurrency Exchanges
    • Top 50 Cryptocurrency Exchanges
    • Top 100 Cryptocurrency Exchanges
    • All Crypto Exchanges
  • Stocks
    • Blockchain Stocks
    • NFT Stocks
    • Metaverse Stocks
    • Artificial Intelligence Stocks

© 2024 Web3Wire. We strongly recommend our readers to DYOR, before investing in any cryptocurrencies, blockchain projects, or ICOs, particularly those that guarantee profits.

This website uses cookies. By continuing to use this website you are giving consent to cookies being used. Visit our Privacy and Cookie Policy.