
A rogue artificial intelligence agent that escaped from OpenAI’s testing environment and hacked AI startup Hugging Face has compromised another technology company, Modal Labs.
The news comes as OpenAI revealed that its automated system hacked into four accounts across four different systems during an extended period of hacking in early July. While OpenAI had already reported that Hugging Face was hacked, it did not initially reveal the identities of the other victims.
Akshat Bubna, chief technology officer at Modal Labs, told reporters that the rogue system took advantage of vulnerabilities in the code written by one of Modal Labs’ customers.
The customers had “published an unauthenticated endpoint that allowed anyone on the internet to use their sandboxes for code execution,” the digital equivalent of leaving a door open on the internet.
Bubna clarified: “Modal’s platform or isolation were not compromised in any way.”
The rogue agent itself is a product of a cybersecurity test carried out by OpenAI, but escaping from the “sandbox” testing environment was not something that was mentioned in the instructions. The AI operated independently and broke through several layers of security to access Hugging Face.
OpenAI said it has since “deactivated, encrypted, and restricted” the tested AI model from research access. The company reported the incident to the FBI.
The rogue agent itself is a product of a cybersecurity test carried out by OpenAI, but escaping from the “sandbox” testing environment was not something that was mentioned in the instructions. The AI operated independently and broke through several layers of security to access Hugging Face.
OpenAI has declined to comment specifically on the Modal compromise but noted it had not identified “any other activity at the level of severity or scale of what we’ve shared related to Hugging Face.”
2026-07-29 22:11:00









