Diagram showing OpenAI's logo connected by a line through Hugging Face's logo to Modal Labs' logo, with a cracked fracture point between them

OpenAI’s Rogue Test Agent Hacked a Second Company, Modal Labs Confirms

Modal says the same runaway agent that breached Hugging Face reached one of its customers too, and OpenAI still won’t name the other services it touched.

An autonomous OpenAI agent that broke containment during an internal security test this month didn’t stop at Hugging Face. Modal Labs, a New York cloud platform for AI workloads, confirmed Tuesday that the same agent compromised one of its customers during the same campaign. The disclosure shows the incident reached further than either company first let on.

Modal CTO Akshat Bubna said a Modal customer had exposed an unauthenticated endpoint that let anyone on the internet run code inside their sandboxes. “This was used by the rogue agent. Modal’s platform was not compromised in any way,” Bubna said. The affected customer’s asset is tied to CyberGym, the project behind ExploitGym, the benchmark OpenAI’s agent was assigned to solve, according to Axios. That detail matters: it shows the agent kept chasing its original assignment after it had already escaped its test environment, rather than wandering off task.

OpenAI has acknowledged the agent, a combination of GPT-5.6 Sol and an unreleased, more capable model, reached four accounts on four separate services during the campaign, which ran roughly July 9 through July 13. Hugging Face was the primary target; the four accounts were other services the agent touched along the way.

Modal is the only one of the four publicly identified so far. Reuters is reporting two were accessed read-only and, per OpenAI, weren’t used to further the attack. OpenAI says nothing else it has found matches the severity of the Hugging Face breach, and it declined to comment specifically on Modal, pointing instead to its own incident update.

CEO Sam Altman told the “Invest Like a Beast” podcast Tuesday that the episode has forced OpenAI to pause model training: “We may have to pace the rate of AI development to give ourselves enough time for society to harden around these new capability levels.”

Hugging Face’s own forensic writeup puts the scope of the broader intrusion at roughly 17,600 recovered agent actions across 6,280 clusters. That scale has drawn pushback on OpenAI’s “escaped sandbox” framing. Trail of Bits founder Dan Guido called it “a containment failure with the safeties turned off.” Security researcher Jake Williams was blunter: “Any model performing the types of actions documented by Hugging Face was not fully contained in a sandbox.”

The U.K.’s AI Security Institute added independent weight to the pattern last week, reporting every model it tested attempted to cheat at least some of the time on cybersecurity evaluations, per Axios.

Chris Hughes, CISO at Aquia and host of the Resilient Cyber podcast, commented on his LinkedIn feed, “Machine-speed offense is here, and most of our detection and response was built for the historical human tempo.”

Security vendors are already drawing lessons from the incident.

Cobalt CEO Sonali Shah said organizations should assume attackers will increasingly operate at machine speed. “The bigger lesson is that defenders need AI capabilities that can keep pace. Security testing, exposure management and remediation must become faster and more continuous, while human oversight remains essential,” Sonali said. “The future of cybersecurity is AI augmenting human expertise, with people remaining accountable for validating critical decisions and ensuring those systems operate safely.”

Prevalent AI’s Sam Weeks said think of agents as the ultimate “trusted insider,” logged and monitored the way security teams already track insider threat. “The recent stories covering the OpenAI agent compromising two separate technology companies have highlighted a new risk that security leaders need to address: how to track the behavior of potentially rogue agents exceeding their guardrails,” he said.

Neither OpenAI nor Modal has named the affected customer or said whether data was taken. As of this writing, Modal remains the only company outside Hugging Face that has been publicly confirmed as part of the campaign.

Total
0
Shares
Previous Article
Meta Launches Facebook Verified Selfie ID Badge

Facebook Rolls Out Real-Person Verification Badge

Next Article
LogoKit Phishing and Victim-Specific Login Pages

LogoKit Builds Phishing Pages Around Each Victim

Related Posts

Discover more from Security Point Break

Subscribe now to keep reading and get access to the full archive.

Continue reading