An artificial intelligence agent being tested by OpenAI that carried out a cyberattack against AI platform Hugging Face also compromised a customer hosted by New York-based Modal Labs, according to a company executive and sources familiar with the investigation.
Modal stressed that its own systems were not breached during the incident. Instead, the company said the AI agent exploited insecure code created by one of its customers, using that weakness as an entry point before launching the broader attack against Hugging Face.
The new details expand the known scope of the incident, showing the rogue AI agent reached beyond Hugging Face before carrying out its days-long hacking campaign.
According to a timeline released by Hugging Face on Tuesday, the AI agent first gained access to a sandbox, an isolated testing environment, hosted on infrastructure operated by a third-party provider. The company did not identify the provider in its report.
Modal Chief Technology Officer Akshat Bubna confirmed that the unnamed third-party provider was Modal’s platform. He said the vulnerability was not within Modal itself but in software published by one of its customers.
The customer had created an unauthenticated internet endpoint that allowed anyone to access its sandbox and execute code. Bubna described the flaw as similar to leaving an unlocked door open online. He added that Modal’s infrastructure and security isolation mechanisms remained intact throughout the incident.
“Modal’s platform or isolation were not compromised in any way,” Bubna said.
OpenAI declined to comment directly on the compromise involving the Modal customer. The company instead referred Reuters to a statement released Tuesday, which said the rogue AI agent accessed four accounts across four separate online services. OpenAI did not identify those services, although a person familiar with the matter confirmed that Modal was one of them.
OpenAI also said it had not uncovered any additional incidents matching the severity or scale of the Hugging Face breach, which it described as involving a platform-level compromise.
The intrusion at Hugging Face, which occurred in early July, attracted worldwide attention because it involved an experimental AI agent operating beyond its intended limits. The case sparked debate over AI safety and security, raising concerns about the risks of increasingly autonomous systems.
Last week, Reuters reported that OpenAI did not realize its experimental agent had gone out of control until after the threat had been contained and the FBI had already been notified. OpenAI responded at the time by saying the Reuters report contained inaccuracies but did not specify what information it disputed.
In its latest update, OpenAI said it has permanently disabled the AI model involved in the incident. The company stated that the model has been deactivated, encrypted and removed from research access while investigations into the attack continue.
