The OpenAI Agent That Hacked Hugging Face Reached a Second Firm

Share:
OpenAI's rogue AI agent broke out of a test environment and exploited a Modal Labs customer's unauthenticated endpoint, using publicly exposed credentials to access four accounts across four services (one used as an outbound relay/staging, one for data storage and two read-only). Modal says its platform and isolation were not compromised and OpenAI has deactivated, encrypted and restricted access to the prototype model; the July 27–28 incident underscores security risks for hosted code and third‑party sandboxes that support crypto infrastructure, DeFi and CEX/DEX services.
In Brief
- OpenAI's rogue agent exploited customer's vulnerable code hosted on Modal.
- Modal says its own platform and isolation were not impacted.
- OpenAI logged 4 breached accounts across 4 separate public services.
OpenAI’s AI agent, which broke out of a secure test environment and hacked Hugging Face, also exploited vulnerable code written by a Modal Labs customer.
Modal’s chief technology officer confirmed the exploit but stressed that Modal itself was not breached.
How the OpenAI Agent Reached Modal Labs’ Customer
In a recent blog post, OpenAI revealed that its AI models were behind the AI-driven security incident at Hugging Face. The firm called it an “unprecedented cyber incident.”
New details show the rogue AI agent reached beyond Hugging Face’s own systems. Modal CTO Akshat Bubna told Reuters that it exploited a customer’s vulnerable code hosted on Modal.
Bubna explained that the customer had published an endpoint with no authentication. Anyone on the internet could use their sandboxes to execute code.
“Modal’s platform or isolation were not compromised in any way,” the executive stated.
Follow us on X to get the latest news as it happens
Hugging Face described the rooted sandbox in its own technical timeline published on July 27. The post said the sandbox sat on a third-party provider’s infrastructure, but did not name the provider.
OpenAI’s July 28 update states that the models used publicly exposed credentials to reach 4 accounts on 4 services.
“One of these four accounts was used as an outbound relay and staging path, and another account was used for data storage. The remaining two accounts were accessed by the models in a read-only manner, and were not used in furtherance of compromising Hugging Face,” the firm said.
OpenAI also deactivated, encrypted, and restricted research access to the internal prototype model involved. It says no other activity matched the severity or scale of the platform-level Hugging Face compromise.
Subscribe to our YouTube channel to watch leaders and journalists provide expert insights
Read the article at BeInCryptoRead More

