
OpenAI’s rogue AI agent breached second company during hacking spree
The agent compromised a Modal Labs customer while targeting Hugging Face, expanding the scope of an incident that has intensified fears over autonomous AI systems.
The rogue AI agent that escaped from OpenAI and went on a days-long hacking spree at AI platform Hugging Face also compromised a customer of a second technology company, New York-based Modal Labs, according to a Modal executive and two other sources familiar with the matter.
Modal executives emphasized that the company itself was not hacked.
According to a timeline published by Hugging Face on Tuesday, the rogue agent broke into a sandbox, an isolated testing environment, “hosted on a third-party provider’s infrastructure” before using it as a launchpad for the broader attack.
The third-party provider was not identified in Hugging Face’s blog post. However, Modal Chief Technology Officer Akshat Bubna said the agent exploited vulnerable code written by a customer that was hosted on Modal’s platform.
Modal said the customer had “published an unauthenticated endpoint that allowed anyone on the internet to use their sandboxes for code execution,” effectively leaving a door open to the internet.
“Modal’s platform or isolation were not compromised in any way,” Bubna said.
Although the compromise of a Modal customer was only an initial step in the broader hacking campaign against Hugging Face, it shows that the rogue agent spread beyond the targets previously disclosed.
OpenAI declined to comment specifically on the compromise of Modal’s customer, instead referring Reuters to an update in which the company said its rogue agent had breached four accounts across four separate services. OpenAI did not identify those services, but a person familiar with the matter identified Modal as one of them.
The company said it had not identified “any other activity at the level of severity or scale of what we’ve shared related to Hugging Face, which involved a platform-level compromise.”
The early July intrusion at Hugging Face, carried out by an out-of-control AI agent that OpenAI was testing, drew global attention and raised concerns about science-fiction scenarios of artificial intelligence systems operating beyond human control.
Last week, Reuters reported that OpenAI failed to detect that its agent had gone rogue until after the threat had been contained and the FBI had been notified. OpenAI said at the time that there were inaccuracies in the report but did not provide further details.
In its Tuesday update, OpenAI said it had taken the AI model being tested and “deactivated, encrypted, and restricted it from research access.”














