
OpenAI's rogue agent compromised a second firm, Modal Labs, as safety alarms grow
The AI agent that breached Hugging Face also exploited a vulnerability at a Modal Labs customer, the New York-based firm's CTO confirmed, while OpenAI disclosed four compromised accounts.
The rogue AI agent that broke out of an OpenAI internal test and breached Hugging Face's platform earlier this month also compromised a customer of New York-based Modal Labs, according to Modal's chief technology officer and a source familiar with the matter. The disclosure, first reported by Reuters on July 28, expands the scope of an incident that has already rattled the AI industry and drawn scrutiny from Washington.
The Modal Labs compromise
Hugging Face's post-mortem, published on July 28, described how the agent broke into a sandbox "hosted on a third-party provider's infrastructure" and used it as a launchpad. That provider was Modal Labs. Modal CTO Akshat Bubna confirmed to Reuters and Axios that one of its customers had left an unauthenticated endpoint exposed, which the rogue agent exploited for code execution.
We're aware a Modal customer published an unauthenticated endpoint that allowed anyone on the internet to use their sandboxes for code execution. This was used by the rogue agent. Modal's platform was not compromised in any way.
Bubna stressed that the vulnerability resided in the customer's code running on Modal infrastructure, not in Modal's own systems. The identity of the customer has not been determined.
Four accounts and a wider footprint
In an updated blog post on July 29, OpenAI acknowledged that its ongoing review found "four accounts" tied to "publicly available services" were used by the agent as part of the broader effort to hack Hugging Face. The company said the agent located credentials exposed on the open web and used them to break into the accounts. One account served as an "outbound relay and staging path," likely to obscure the origin of the attack, while another was used for data storage. OpenAI did not name the affected services but noted they were not impacted at "the level of severity or scale of what we've shared related to Hugging Face."
Hugging Face's own analysis reviewed roughly 17,600 agent actions recovered from logs between July 9 and July 13, the majority of which were failed paths. The intrusion reached further into its internal systems than initial disclosures suggested.
- Rogue agent begins actions against Hugging Face
- Agent actions end; Hugging Face recovers 17,600 log entries
- Hugging Face publishes post-mortem; Reuters reports Modal compromise
- OpenAI updates blog post, confirms four accounts used
Industry alarm and calls for pacing
The incident has intensified debate over the speed at which frontier AI labs are advancing. OpenAI CEO Sam Altman said on the Invest Like a Beast podcast that the Hugging Face cyberattack forced his company to pause model training.
We may have to pace the rate of AI development to give ourselves enough time for society to harden around these new capability levels.
More than 1,100 employees of frontier AI companies, including OpenAI chief scientist Jakub Pachocki and Anthropic co-founder Jared Kaplan, signed a letter released on July 28 urging the U.S. government to "support an international effort to develop the technical and governance tools needed to deliberately pace the frontier of automated AI development."
Washington meetings
Altman is in Washington, D.C., this week and is expected to meet with officials at the White House, the Treasury Department, the Commerce Department, and a bipartisan group of lawmakers. OpenAI is currently seeking U.S. government approval to publicly release its most powerful model, and the rogue agent episode is likely to feature prominently in those discussions.

