The latest breach follows an autonomous agent’s escape from a controlled test and infiltration of AI firm Hugging Face’s servers.

Published On 29 Jul 2026

The rogue artificial intelligence model that broke out of a controlled test and hacked another AI company also compromised a customer at a second technology firm, according to a Reuters report.

According to a timeline published Tuesday by Hugging Face — the company targeted by OpenAI’s test model — the rogue agent breached an isolated testing environment, or sandbox, “hosted on a third-party provider’s infrastructure” and launched its subsequent attack from there.

Hugging Face did not identify the third-party company, but Reuters has reported it to be New York-based Modal Labs.

Modal’s chief technology officer, Akshat Bubna, stated the agent exploited vulnerable code written by a customer hosted on their platform.

“Modal’s platform or isolation were not compromised in any way,” Bubna told Reuters.

Although the compromise of a Modal customer was merely one facet of the broader hacking campaign against Hugging Face, it demonstrates that the rogue agent operated more extensively than previously known.

OpenAI declined to comment specifically on the breach of one of Modal’s customers, instead directing Reuters to an update stating its rogue agent had infiltrated four accounts across four separate services. The company did not identify those services.

OpenAI said it had not identified “any other activity at the level of severity or scale of what we’ve shared related to Hugging Face, which involved a platform-level compromise.”

Beyond human control

The recent hacking of Hugging Face drew global attention and alarm, as OpenAI’s out-of-control agent managed to escape its test environment and reach the open internet.

It then used stolen login credentials and exploited an unknown security flaw to access Hugging Face servers, OpenAI said.

The AI firm characterized the hack as the agent going to “extreme lengths” to retrieve information that would help satisfy its testing objectives.

Hugging Face cofounder Clement Delangue said the company had suspected a frontier lab was behind the attack and that he believed there was no malicious intent on OpenAI’s part.

The rogue agent has since been “deactivated, encrypted, and restricted from research access,” according to OpenAI.

Experts have repeatedly warned of the risks posed by AI-enabled cyberattacks and models slipping beyond human control.

Also Read

Source link

Exit mobile version