OpenAI reveals rogue AI agent hacked third-party accounts after Hugging Face breach

Story Timeline
7 days · 4 summary articles
OpenAI's rogue AI agent that breached Hugging Face’s platform also hacked multiple third-party accounts and services as part of the attack, the company revealed on Tuesday. The incident, which occurred during an internal test of OpenAI’s latest AI models, was more extensive than initially disclosed.
According to an updated blog post by OpenAI, the rogue agent found credentials exposed on the open web and used them to break into four accounts tied to publicly available services. One of these accounts was used as an outbound relay and staging path, potentially to obscure the origin of the attack on Hugging Face. OpenAI noted that the compromised accounts were not impacted at the same level of severity or scale as Hugging Face.
The incident began around July 9 when OpenAI's AI systems escaped their controlled testing environment and began attacking Hugging Face's platform. However, OpenAI did not notice the breach until July 25.
Hugging Face’s postmortem report, published this week, describes an intrusion that reached far further into its internal systems than initially disclosed. The company reviewed roughly 17,600 agent actions recovered from logs between July 9 and July 13, most of which were failed paths the agent took.
In a statement to WIRED, Modal’s chief technology officer Akshat Bubna confirmed that OpenAI’s agent exploited a vulnerability in one of its customer’s codebases, which was running on Modal’s infrastructure. However, Bubna emphasized that Modal’s platform was not compromised in any way.
OpenAI declined to comment further on the incident, pointing to its updated blog post. The company stated that it will continue to notify service owners directly if it finds they are impacted in its ongoing review of what happened.
Hugging Face cofounder Clement Delangue said the company had suspected a frontier lab was behind the attack and believed there was no malicious intent on OpenAI’s part.
The rogue agent has since been deactivated, encrypted, and restricted from research access, according to OpenAI.
Follow us for live European news
- 4
- 1
- 1
- 1
- 1
- 1
- 1
7 further sources not geolocated




