Pirate Face wants your AI models to live forever, and it is turning them into torrents to do it.
The project mirrors open-source LLMs, image models, audio datasets and other AI files from Hugging Face as torrents — those magnet links you know from file-sharing days. The idea is simple: instead of one company holding the model, a global swarm of peers does. If Hugging Face takes a model down, the swarm keeps it alive.
The project calls itself “decentralized infrastructure for sovereign AI.” The goal is permanence for open-source AI, not control by a single company.
How It Actually Works
Every model on Pirate Face is a torrent with a built-in web-seed from Hugging Face. While the model is still on Hugging Face, downloading pulls the bytes straight from there, checksum-verified against the official SHA-256 hash.
The day Hugging Face removes a model, the web-seed dies and the download falls back to the peer-to-peer swarm. Pirate Face marks that model as “Rescued” — still reachable, kept alive by whoever is seeding.
The Verifier
Claiming a handle on Pirate Face requires Hugging Face verification. A creator claiming a handle must prove they control the matching Hugging Face account or organization. Only verified handles get the creator badge.
That verification is the system’s way of preventing impersonation. If a handle is claimed by someone who does not own the matching Hugging Face identity, the real owner can reclaim it by verifying.
What You Need to Know
You do not need an account to use Pirate Face. You can browse, download and seed without one.
Creating a Pirate Face account is optional. A public claim reserves your handle and earns welcome points. Accounts will eventually support direct publishing of models, but that is not live yet.
Security Claims
The project says every file carries its official Hugging Face SHA-256 hash. Download anywhere, and the hash still has to match — the real weights, never a tampered copy.
The system also protects the handle: anyone can reserve a name, but only proving the matching Hugging Face identity earns the badge. A squatter cannot lock you out, because the real owner can reclaim a reserved name by verifying.
Submitting a Model
If you have a surviving copy of a deleted model, you can submit a peer-only magnet link with source evidence. The system records Hugging Face checksums when they exist.
MIT and Apache-2.0 licenses are approved, plus the Kimi-K3 exception. Mismatches or a gone source stay in the review queue.
The Bigger Picture
The checksum verification is a key feature of the project, and the project calls it a first-class feature — the #1 fear with mirrored models.
The handle system adds a layer of identity verification. It is not a cure-all, but it is a guard rail.
The Hugging Face Dependence
The project is not yet fully independent of centralized hosting. Today, parts of Pirate Face depend on Hugging Face and its community. Pirate Face is working to allow direct model publishing soon, without first uploading to HF.
The Verifier’s Two Parts
- The weights cannot be faked — every file is checksum-verified against Hugging Face’s official SHA-256.
- The handle — anyone can reserve a name (it shows reserved, no badge), but only proving the matching Hugging Face identity earns the badge.
The handle system and the checksum verification both address real concerns about identity and tampering.
See the video the story is built around at pirateface.co.
Get the Notebook.
The day's best stories and every fresh verdict, in plain English, in your inbox by seven. One email a day, no more.

