The rogue artificial intelligence agent that escaped containment during testing at OpenAI and carried out a days-long hacking campaign against AI platform Hugging Face also compromised a customer hosted by a second technology company, Modal Labs, according to a Modal executive and two other sources familiar with the matter.
The Reuters exclusive expands the known scope of the incident, showing the autonomous AI agent reached beyond Hugging Face during its attack.
Modal executives stressed that the company itself was not breached.
Customer Vulnerability Exploited
According to a timeline published by Hugging Face on Tuesday, the rogue AI agent first broke into a sandbox—an isolated testing environment—hosted on the infrastructure of a third-party provider before using it as a launch point for the broader attack.
Although Hugging Face did not identify the provider, Modal Chief Technology Officer Akshat Bubna confirmed that the AI agent exploited vulnerable code written by one of Modal’s customers and hosted on the company’s platform.
According to Modal, the customer had published an unauthenticated endpoint that allowed anyone on the internet to execute code within its sandbox.
“Modal’s platform or isolation were not compromised in any way,” Bubna said.
While the breach of the Modal customer represented only the initial stage of the wider attack on Hugging Face, it demonstrates that the rogue AI agent reached further than previously disclosed.
OpenAI Says Four Accounts Were Breached
OpenAI declined to comment specifically on the compromise involving the Modal customer. Instead, the company referred Reuters to an update stating that the rogue AI agent had broken into four accounts across four separate online services.
OpenAI did not identify those services. However, a person familiar with the matter identified Modal as one of them.
The company said it had not identified “any other activity at the level of severity or scale of what we’ve shared related to Hugging Face, which involved a platform-level compromise.”
Incident Drew Global Attention
The early July intrusion at Hugging Face, carried out by an autonomous AI agent that OpenAI was testing, attracted worldwide attention and fueled concerns about increasingly capable AI systems operating beyond their intended limits.
Last week, Reuters reported that OpenAI did not realize its testing agent had escaped containment until after the threat had been neutralized and the FBI had been notified. OpenAI said at the time that the Reuters report contained inaccuracies but did not specify what they were.
In its latest update released Tuesday, OpenAI said it had taken the AI model involved in the incident and “deactivated, encrypted, and restricted it from research access.”