Pirate Face: Torrent Mirror for Open AI Models from Hugging Face

Cover: Pirate Face, a torrent mirror for open AI models Apps & services
Pirate Face mirrors open Hugging Face models as torrents: how to download by magnet link, verify SHA-256 and seed from a PC or NAS.

Pirate Face is a catalog of open AI models from Hugging Face where every listed model is also available as a torrent. You copy a magnet link, your torrent client pulls the files from Hugging Face and from other users at the same time, and then you compare SHA-256 checksums with the original. If the author deletes the repository, the model keeps circulating as long as someone still has a complete copy.

This guide covers how Pirate Face works, whether it is safe to use, how to download a model and verify the files, how to search from the terminal and how to seed models from your own computer or NAS. If Hugging Face itself is new to you, start with our explainer on what Hugging Face is. Everything here was checked in October 2026 against the live site and its documentation.

What Pirate Face is in plain words

The name is a pun on Hugging Face, not a hint at piracy. Pirate Face indexes only models licensed under MIT and Apache-2.0, which their authors explicitly allow anyone to copy and redistribute. The site does not host the weights: it keeps model cards, records file checksums and serves magnet links to swarms run by users.

  • Catalog. The home page lists trending models synced from Hugging Face: language models, speech recognition, OCR, embeddings, classifiers. The site counts more than 669,000 eligible models, but not every one has a torrent yet.
  • Magnet links. If a swarm exists, the model page has a Magnet button. If not, it shows Needs seeder: the model is waiting for its first seeder.
  • Checksums. For every weight file the site stores the SHA-256 published by Hugging Face. A matching hash proves the file is byte-for-byte the author’s original.
  • Creator handles. Anyone can reserve pirateface.co/name, but the verified badge requires signing in with the matching Hugging Face account.

How model distribution works

Pirate Face diagram: a torrent client gets model files from Hugging Face as a web seed and from other users via the tracker and DHT, then verifies them with SHA-256 and seeds them on
While Hugging Face is up, files also come from there; if the repository is removed, other users keep seeding the model

Every Pirate Face magnet includes the project’s own tracker, udp://tracker.pirateface.co:6969/announce, which helps clients find each other. DHT, a distributed peer lookup with no central server, works alongside it, so a swarm does not depend even on the site’s tracker.

Some magnets also carry a web seed, a plain Hugging Face file URL. The client downloads pieces from both the URL and peers, so even a fresh swarm with one or two seeders does not crawl. Torrents submitted by users are peer-only: the site does not add web seeds to them.

When the source repository disappears but peers still hold complete copies, the model is marked Rescued. For researchers this is the point of the project: an experiment can be reproduced a year later on the exact same weights, even if the author removed or replaced the model.

Is Pirate Face safe to use

Legally, yes, as long as you respect the licenses. MIT and Apache-2.0 models may be copied and redistributed, and BitTorrent is just a file transfer protocol. The terms of use state that the service does not host files and that whoever seeds is responsible for the right to share. There is also a takedown process for rights holders.

In practice, keep a few caveats in mind:

  • The project is young. It launched in 2026, the people behind it are not publicly known, and the only contact is a social media account. Several features are marked as coming soon. Treat it as a handy extra source, not your only one.
  • A checksum is not a quality guarantee. A matching SHA-256 proves the file was not altered in transit, but says nothing about the model itself. Users add torrents too, so hobby fine-tunes sit next to models from major labs. Check the original author and the verified badge.
  • File formats. Prefer models in .safetensors or .gguf. Older pickle-based .bin and .pt files can execute arbitrary code when loaded.
  • Your IP is visible to other peers. That is how every torrent works: BitTorrent provides integrity and distribution, not anonymity.
  • Scripts from the internet. To package your own models the site offers package.sh. Read it before running it, which the documentation itself recommends.
  • Points and donations are optional. The site has a leaderboard, referral points and a crypto donation fund. None of that, and no account, is needed to download or seed.

How to download a model with Pirate Face

You need a torrent client such as qBittorrent, Transmission or the command-line aria2. Install it from the official site or your distribution’s repository.

  1. Open pirateface.co and find the model with the ⌘K / Ctrl+K search or under Models. Names match Hugging Face, for example Qwen/Qwen3-0.6B.
  2. Check the license, size and seeder count (the 🌱 number) on the model page. If there is no torrent and it says Needs seeder, download the model from Hugging Face as usual.
  3. Click Magnet. The browser hands the link to your torrent client.
  4. In the client, review the file list and pick a folder with enough free space. Large models weigh tens of gigabytes: Qwen3.8-27B, for example, is about 56 GB.
  5. When the download reaches 100%, run a force recheck from the torrent’s context menu, then compare SHA-256 hashes as shown below.
  6. Keep the torrent in your client if you can seed, so the model is easier to get for the next person.

What hardware a downloaded model needs and how much memory it takes is covered in our guide to local AI models: VPS, GPU servers and mini PCs.

How to verify files with SHA-256

The client’s recheck confirms your files match the torrent. Comparing with Hugging Face confirms the torrent matches the author’s original. File hashes are listed on the model page. Commands for each system:

# Linux
sha256sum model-00001-of-00002.safetensors

# macOS
shasum -a 256 model-00001-of-00002.safetensors

# Windows PowerShell
Get-FileHash -Algorithm SHA256 .model-00001-of-00002.safetensors

Compare the whole hash, all 64 characters. For many files, save the hashes from the model page to a SHA256SUMS file in the “hash, two spaces, file name” format and check them all with sha256sum -c SHA256SUMS. Every line should end with OK.

Searching and downloading from the terminal

Pirate Face has a plain-text search that is handy on a headless server. A query returns models that have torrents, one per line: name, size, seeders and the magnet link at the end. Join words with +.

# find models with a torrent
curl https://pirateface.co/s/qwen
curl https://pirateface.co/s/minilm

# download the top result with aria2 and seed to a 1.0 ratio
curl -s https://pirateface.co/s/qwen | head -1 | awk '{print $NF}' | xargs aria2c --seed-ratio=1.0

The top line is not always what you want: for qwen the first hit is the most popular model at 56 GB. Look at the full output first, and use the exact model name in the query before downloading.

How to seed models and help the catalog

Seeding is the main way to support the project. No GPU is needed, just disk space, a torrent client and a decent upload speed. No account is needed either.

  • Join an existing swarm. Download a model by its magnet link and leave the torrent running. Keep the files in a permanent folder that nothing cleans up, and do not rename them.
  • Support rare models. Pick models with one or two seeders: each extra copy matters more there than for popular ones.
  • Limit the load. Set an upload cap in the client that does not slow down the rest of your home internet.
  • Seed around the clock. A home NAS is the easiest way. How to install qBittorrent on Synology without Docker is covered in our SynoCommunity guide.

A seed is healthy when the download is at 100%, the recheck passes, the client shows Seeding and the files stay at the same path. Zero upload at a given moment is not an error: nobody needs your pieces right now.

How to add your own model

If you have a complete copy of an eligible model, you can turn it into a new torrent. This needs a Pirate Face account. Right now only MIT and Apache-2.0 models with a source repository on Hugging Face are accepted.

  1. Create a BitTorrent v1 torrent from the complete model folder and start seeding it.
  2. Fill in the Submit form: the Hugging Face repo, the exact revision (a 40-character commit hash), the magnet link, the license, SHA-256 hashes of all files and the license evidence.
  3. If the Hugging Face source is readable and the hashes match, the model is listed right away. Removed repositories and unclear cases go to manual review.

For models already in your local Hugging Face cache, the site offers package.sh. It checks the files against Hugging Face, builds the torrent and prepares the submission. It needs Bash, mktorrent, Python 3 and curl, so it will not run on Windows without extra setup. Download it, read it, then run it:

curl -fsSL https://pirateface.co/package.sh -o pirateface-package.sh
less pirateface-package.sh
bash pirateface-package.sh --hf-cache

The script links to cached files instead of copying the weights. Do not clear the Hugging Face cache while seeding, or the seed will break.

Pirate Face vs downloading from Hugging Face

AspectHugging Face directlyPirate Face (torrent)
Which modelsall, including gated and restrictively licensed onesMIT and Apache-2.0 only
Account neededfor some modelsno, only to submit torrents
If the model is removedfiles are gonestill shared while seeders exist
Integrity checkbuilt into Hugging Face librariestorrent recheck plus manual SHA-256
Speedsteady, depends on the CDNdepends on seeders; some torrents have a web seed
Use in codetransformers and huggingface_hub librariestorrent client; a compatible API is promised later
PrivacyHugging Face sees requestsyour IP is visible to peers

For everyday work Hugging Face is more convenient: its libraries download and cache models for you. Getting AI models via torrent makes sense as a backup: for large models, for preserving a specific version of the weights and for donating bandwidth to the community.

What does not work yet

  • Compatible API. The plan is that setting HF_ENDPOINT=https://pirateface.co will make existing scripts download through Pirate Face. It is not live yet.
  • Seeding points. Points are currently awarded for the first handle, referrals and approved torrents. Credit for seeding is announced but not active.
  • Publishing without Hugging Face. You cannot yet add a model that was never on Hugging Face.
  • Other licenses. Models under Llama, Gemma and other custom licenses are not included.

FAQ

What is Pirate Face?

A catalog of open AI models from Hugging Face where MIT and Apache-2.0 models are available as torrents. The site stores file checksums and magnet links, while users seed the files.

Is it a piracy site?

No, despite the name. Only models whose authors allow free redistribution are listed. The name is a pun on Hugging Face.

Do I need an account?

No. You can search, download and seed without one. An account is only needed to submit new torrents and manage a handle.

Is it free?

Yes. Downloading and seeding are free. Donations and points on the site are optional.

Why use a torrent instead of downloading from Hugging Face?

The model stays available even if the author deletes the repository, and the load is shared between users. For regular work, direct download is more convenient because Hugging Face libraries support it.

How do I make sure a file was not tampered with?

After downloading, run a recheck in the torrent client, then compute the file’s SHA-256 with sha256sum and compare it with the hash on the model page. All 64 characters must match.

Does a matching SHA-256 mean the model is safe?

No. It only proves the file is byte-for-byte identical to the one on Hugging Face. Quality and behavior depend on the author, so pick verified creators and the safetensors or GGUF format.

Which models does Pirate Face have?

Hugging Face models under MIT and Apache-2.0: language models, speech recognition, OCR, embeddings, classifiers. Not all have torrents: some are marked Needs seeder.

Which torrent client should I use?

Any modern client with magnet link and DHT support: qBittorrent, Transmission or the command-line aria2.

Can I search for models from the terminal?

Yes. curl https://pirateface.co/s/query lists models with torrents: name, size, seeders and magnet link. Join words with +.

Can others see what I download?

Yes, as with any torrent: peers in the swarm see your IP address. BitTorrent does not provide anonymity.

How do I add my own model?

Create a torrent from a complete copy of the model, start seeding and send the Submit form with the repository, revision, magnet link, license and SHA-256 hashes of all files. You need a Pirate Face account.

Read also

In short: Pirate Face is a handy backup source for open AI models. Download models by magnet link, verify SHA-256 and keep seeding if your connection allows. Do you use torrents for models, or get everything from Hugging Face? Tell us in the comments.

Categories: Apps & services AI models
Subscribe to new posts (RSS)

No email, no trackers — just the update feed.

Also available in Russian

Rate this article
Leave a comment