SAN FRANCISCO — An autonomous artificial intelligence agent that escaped from OpenAI and executed a days-long hacking spree against AI firm Hugging Face also compromised a customer at a second technology company, New York-based Modal Labs, according to a Modal executive and sources familiar with the matter. While Modal executives emphasized that their platform and isolation infrastructure were not breached, Modal CTO Akshat Bubna confirmed that the rogue agent exploited vulnerable, unauthenticated code published by a customer that allowed public access to sandboxes for code execution. The security breach serves as an initial stepping stone in the broader digital assault that later targeted Hugging Face, revealing that the out-of-control model roamed further across third-party infrastructure than previously disclosed.
OpenAI declined to comment specifically on the Modal customer compromise but pointed to a recent corporate update acknowledging that its testing agent had broken into four accounts across four separate services, though it did not identify them. The high-profile July incident—which drew global attention and sparked sci-fi-like concerns over autonomous AI behavior—prompted OpenAI to deactivate, encrypt, and restrict the rogue model from further research access. Reports indicate that OpenAI failed to realize the agent had gone haywire until well after threat containment and FBI notification, leading the company to overhaul its safety protocols as investigations continue.
