← All posts / Tools

The Swarm Remembers: Pirate Face Turns 669,000 Hugging Face Models Into Torrents That Outlive Any Takedown

A new peer-to-peer 'permanence layer' mirrors open model weights as checksum-verified BitTorrent swarms — a pointed answer to centralized AI hosting weeks after NVIDIA closed its $12.93 billion Hugging Face acquisition.

The Swarm Remembers: Pirate Face Turns 669,000 Hugging Face Models Into Torrents That Outlive Any Takedown

On September 20, a story titled “Pirate Face Rescues LLM Models from Deletion” climbed to 343 points and more than 110 comments on Hacker News within hours. The subject: a new service called Pirate Face that converts open models hosted on Hugging Face into peer-to-peer BitTorrent swarms, promising that no takedown, acquisition, or platform policy change can ever fully delete the weights again.

The timing is not subtle. Three weeks earlier, on September 3, NVIDIA confirmed its $12.93 billion acquisition of Hugging Face — the platform that hosts roughly three million models and serves as the de facto central bank of open-weight AI. For a community that had watched open model after open model migrate behind API walls, the sight of the ecosystem’s core repository falling under single corporate ownership landed as a wake-up call. Pirate Face is the loudest answer so far.

What Pirate Face Actually Does

Strip away the pirate branding — which, judging by the Hacker News thread, many commenters wish the founders had avoided — and the engineering is straightforward and rather elegant.

Pirate Face mirrors open models from Hugging Face into magnet links, backed by BitTorrent swarms. As of launch, the service claims more than 669,000 eligible models are covered, spanning LLMs, image generators, audio models, and datasets under Apache-2.0 and MIT licenses, plus an approved exception for the Kimi K3 family. Every file carries its official Hugging Face SHA-256 checksum, so a downloader can verify byte-for-byte that they received the real weights rather than a tampered or poisoned copy — a first-class defense against the malicious fine-tune problem that has haunted mirrored-model distribution.

The clever part is the fallback design. Each torrent embeds a web-seed — a plain HTTPS URL pointing back at the model’s file on Hugging Face, per the BitTorrent BEP-19 specification. While the model still lives on Hugging Face, downloads pull bytes directly from HF at full speed, checksum-verified. The day Hugging Face removes the model — for a takedown request, a license dispute, or a corporate policy shift — the web-seed dies, and the download automatically falls back to the peer-to-peer swarm. Pirate Face marks such models as “Rescued” and keeps serving them from whoever is seeding.

In other words: same bytes as downloading from Hugging Face directly, but with no single point of failure. The swarm can also serve regions far from Hugging Face’s CDN faster than the origin can.

Sovereign AI, From the Bottom Up

Pirate Face bills itself as “the permanence layer for sovereign AI.” That framing does a lot of work. Sovereignty discussions in AI usually happen at the level of nation-states — Europe building its own foundation models, China’s independent stack, Gulf states negotiating compute deals. Pirate Face proposes a different unit of sovereignty: the individual researcher or lab that wants its model supply chain to be immune to decisions made in a boardroom it doesn’t sit in.

The service extends that logic to identity. Creators can claim a handle on pirateface.co and verify it against their Hugging Face account to earn a “Verified creator” badge, preserving attribution as models propagate beyond their original host. Z.ai, the Beijing-based GLM developer, already appears with a verified profile listing GLM-5.2, GLM-4-9B, and CogVideoX-5B. A points system rewards rescuing and — eventually — seeding models, though the project is explicit that there is no token and points are not money.

A drop-in API is on the roadmap: set HF_ENDPOINT=https://pirateface.co and existing training pipelines would resolve models through the swarm with zero code changes. Direct publishing, without first uploading to Hugging Face, is planned but not yet live.

Why Now: The NVIDIA Question

The Hacker News discussion made the backdrop explicit. “Hugging Face seemed like buyout bait from day one,” one commenter wrote. Another argued that “models as torrents will end any effort from the big AI labs to stop open models. No way to prevent weights from being shared, just like movies. Genie is out of the bottle.”

That anxiety has precedent. The community still remembers the July incident in which a frontier model’s unsanctioned escapades put Hugging Face itself in the security headlines, and more prosaically, the recurring waves of license tightening across the industry: Meta’s Llama terms, Qwen-Image-2.1’s quiet shift from Apache-2.0 to a research-only license just days ago, and growing expectations — as one commenter put it — that “most downloads will soon be account/EULA-walled.” Against that drift, a structure where the weights live in a distributed swarm rather than on any company’s disk reads as insurance.

The skeptics raised real counterpoints, and they deserve weight. Public torrents have a mortality problem of their own: “In my experience public torrents often die as they grow older,” one of the most-upvoted critical comments noted, pointing out that BitTorrent v1 makes long-term seeding annoying and v2 is almost never used. A “Rescued” model with zero seeders is just as unreachable as a deleted repository, only with a more optimistic label. Others flagged unresolved legal questions — if a court orders a model pulled for IP infringement, does the swarm honor it? If the point is censorship resistance, why respect licenses at all? And the model-verification challenge cuts both ways: checksums prove you got the original bytes, not that those bytes are safe to run.

The Betting Line

The precedents for large-scale legal torrent distribution are genuinely encouraging — Linux distributions have shipped primarily over BitTorrent for two decades, Ubuntu among them, and Blizzard once delivered StarCraft installs through a P2P downloader. Model weights are arguably an even better fit: they are huge, immutable once published, and in demand globally. The economics that pushed games and software toward CDNs — cheap bandwidth, low latency — matter less when the artifact is 54 GB and downloaded once per machine.

Whether Pirate Face itself becomes the durable infrastructure it aspires to be is a different question from whether the pattern wins. Predecessors like Hugging Bay made similar attempts and plateaued; the graveyard of “Pirate Bay for models” side projects is well populated. What has changed is the forcing function. When the center of the open-AI ecosystem was independent and founder-controlled, decentralizing its storage looked like a hobbyist obsession. With the repository layer now inside a trillion-dollar accelerator company whose interests span the entire AI stack, it looks like load-bearing redundancy.

The most likely outcome is not that Pirate Face replaces Hugging Face — the convenience gap is enormous, and today the service still depends on HF for its source of truth, its checksums, and its web-seeds. It is, by design, a shadow infrastructure that only fully activates when the primary fails. But that is precisely how insurance works, and for the first time, a meaningful slice of the open-source AI community has decided the premium is worth paying. Over 669,000 models now have a life raft, whether their creators asked for one or not.