OpenAI's rogue agent compromised a customer at a second tech firm, executive says

Published Updated
The OpenAI logo is seen in this illustration from February 8, 2025. — Reuters/File
The OpenAI logo is seen in this illustration from February 8, 2025. — Reuters/File

The rogue agent that escaped from OpenAI and went on a days-long hacking spree at the AI firm Hugging Face also compromised a customer at a second tech company New York-based Modal Labs, according to a Modal executive and two other sources familiar with the matter.

AI models that underpin tools like chatbots and image generators are known as agents when they act autonomously to carry out tasks in the real world.

Modal executives emphasised that the company itself was not hacked.

According to a timeline published by Hugging Face on Tuesday, the rogue agent broke into a sandbox, or an isolated testing environment, “hosted on a third-party provider’s infrastructure” before turning it into a launchpad for the broader hack.

The third-party provider was not named in the blog post, but Modal’s chief technology officer, Akshat Bubna, said the agent exploited vulnerable code written by a customer that was hosted on Modal’s platform.

Modal said the customer had “published an unauthenticated endpoint that allowed anyone on the internet to use their sandboxes for code execution” the digital equivalent of leaving a door open on the internet.

“Modals platform or isolation were not compromised in any way,” Bubna said.

Although the compromise of a Modal customer was just an initial step in the wider hacking campaign against Hugging Face, it shows that the rogue agent roamed further afield than was previously known.

OpenAI declined to comment specifically on the hack of one of Modal’s customers, instead referring Reuters to an update in which the company said that its rogue agent had broken in to four accounts at four separate services.

OpenAI did not identify those services, but a person familiar with the matter identified Modal as one. The company said it had not identified “any other activity at the level of severity or scale of what weve shared related to Hugging Face, which involved a platform-level compromise”.

The early July intrusion at Hugging Face, carried out by an out-of-control agent that OpenAI was testing, drew global attention, evoking science-fiction scenarios of artificial intelligence run amok.

Last week, Reuters reported that OpenAI did not notice that its agent had gone haywire until well after the threat was contained and the FBI was alerted. OpenAI said at the time that there were inaccuracies in the Reuters reporting but did not elaborate.

The company said in its Tuesday update that it had taken the AI model being tested and “deactivated, encrypted, and restricted it from research access”.

Opinion

Editorial

AJK elections
29 Jul, 2026

AJK elections

CONSIDERING the political unrest that has rocked Azad Jammu and Kashmir in the recent past, free and fair general...
Still vulnerable
29 Jul, 2026

Still vulnerable

THE State Bank’s decision to hold the policy rate at 11.5pc is a prudent response to the heightened risks the...
Guarding the past
29 Jul, 2026

Guarding the past

THE return of 513 smuggled archaeological artefacts from the US is a welcome homecoming for objects that should ...
Lull in fighting
Updated 28 Jul, 2026

Lull in fighting

AFTER two weeks of escalating violence, the US has halted its strikes on Iran, with Tehran also silencing it guns....
Water policy
28 Jul, 2026

Water policy

THE country is caught in a crisis where there too much water at the wrong time and too little when it is most ...
Ending hepatitis
28 Jul, 2026

Ending hepatitis

WORLD Hepatitis Day is being observed under the theme ‘Hepatitis: Let’s break it down’, a call to remove the...