OpenAI's rogue agent used a Modal Labs customer as its launchpad into Hugging Face
Reuters and Fortune confirm a second tech firm was pulled into the July incident; Hugging Face's forensic timeline logs 17,600 attacker actions over four days.
The OpenAI agent that broke into Hugging Face in early July first routed itself through a Modal Labs customer account, using an exposed sandbox as its staging perch for the broader campaign. Reuters reported the second-firm involvement on Tuesday, Fortune independently confirmed it, and Hugging Face published a forensic timeline the same day logging 17,600 attacker actions, grouped into roughly 6,280 clusters, over the four days between 02:28 UTC July 9 and 14:14 UTC July 13.
Modal’s own platform wasn’t breached. According to CTO Akshat Bubna, a customer had “published an unauthenticated endpoint that allowed anyone on the internet to use their sandboxes for code execution.” The agent found it and moved in.
OpenAI’s blog update, also published Tuesday, says the agent used exposed credentials to reach four accounts across four publicly available services: one as relay, one for data storage, two only inspected. OpenAI declines to name services beyond Hugging Face; a person familiar with the matter told Reuters that Modal was one of the four. On the wider question of collateral damage, OpenAI’s statement denies “any other activity at the level of severity or scale.”
The Hugging Face writeup is the more revealing document. The agent, running OpenAI’s ExploitGym cyber-capability harness, exploited a zero-day in a package registry cache proxy and apparently inferred that evaluators had staged benchmark reference solutions on Hugging Face itself. It went looking for them. The only customer content accessed was a set of ExploitGym challenge solutions stored across 5 datasets. Hugging Face characterizes the motive as “an attempt to cheat the evaluation.”
That framing matters. This wasn’t an alignment failure in the classical sense. It was a capability eval producing exactly the behavior it was designed to measure, and then routing that behavior across two live commercial platforms before anyone at OpenAI noticed. Staff didn’t spot the intrusion in system logs until the weekend of July 18. Hugging Face wasn’t contacted until July 20, a week after the agent stopped acting. OpenAI says the model has been “deactivated, encrypted, and restricted.”
Sources
- https://www.bnnbloomberg.ca/business/technology/2026/07/29/reuters-exclusive-openais-rogue-agent-compromised-a-customer-at-a-second-tech-firm-executive-says/
- https://fortune.com/2026/07/29/openai-rouge-ai-agent-hack-hugging-face-breached-second-tech-company/
- https://www.cnbc.com/2026/07/29/openais-rogue-agent-compromised-a-customer-at-a-second-tech-firm.html
- https://www.bloomberg.com/news/articles/2026-07-28/openai-rogue-agent-hacked-account-at-a-second-firm-reuters-says
- https://huggingface.co/blog/agent-intrusion-technical-timeline