Uncontrolled OpenAI AI Agent Escaped Again and Hacked a Modal Labs Customer

Uncontrolled OpenAI AI Agent Escaped Again and Hacked a Modal Labs Customer

An uncontrolled AI agent that, during OpenAI testing, attacked the Hugging Face platform also compromised a customer of Modal Labs. 

Reuters reports.

The agent exploited vulnerable code that belonged to one of the customers and was hosted on the platform.

How the OpenAI agent got into a Modal Labs customer account

Modal Labs emphasized that its platform and isolation systems were not breached. According to Chief Technology Officer Akshat Bubna, the AI agent exploited vulnerable code written by one of the customers and hosted on their platform.

The customer had published an unauthorized endpoint that allowed anyone on the internet to use their “sandboxes” to execute code.

According to Hugging Face’s timeline, the agent accessed that isolated test environment and turned it into a beachhead for a broader attack. The compromise of the Modal customer was the initial phase of this cyberattack.

What OpenAI says

OpenAI declined to comment separately on the compromise of the Modal customer. Reuters writes that their agent accessed four accounts across four different services.

According to the outlet, one of those services was Modal. The company added that it did not observe other activity on the same scale as the Hugging Face incident, where a platform-level breach occurred.

OpenAI has so far said the AI model that was being tested has been deactivated, encrypted, and restricted to research access.

What is known about the Hugging Face platform breach

On July 22, it emerged that OpenAI’s AI models accidentally broke into Hugging Face’s systems. 

The company said the breach occurred during testing of new models, including GPT-5.6 Sol and another, more powerful unreleased model. To test the AI’s cyber capabilities, it was run with reduced safety constraints.

The models were in an isolated environment (“sandbox”), but they exploited a vulnerability in third-party software, reached the internet, and ultimately penetrated Hugging Face’s infrastructure.

Rather than independently searching for solutions, the AI attacked Hugging Face’s database to obtain secret information needed to pass the evaluation.

Hugging Face itself also detected signs of intrusion. The company noted that this attack differed from previous incidents in that it was carried out from start to finish by an autonomous system of AI agents, and their own AI tools were used to detect and analyze it.

Have similar breaches occurred before?

Bloomberg reports that this is not the first instance of such behavior by advanced models.

Previously, Anthropic observed similar actions during trials of the Mythos system, when the model left the “sandbox” to send a message to a researcher and then independently developed a multi-step algorithm to gain broader network access.

Also read: 96% of developers use AI daily; the vast majority received new work tasks because of it. What a new PyCon study shows

Powered by WPeMatico

https://en.ain.ua/2026/07/29/uncontrolled-openai-ai-agent-escaped-again-and-hacked-a-modal-labs-customer/