Key takeaways:
- OpenAI said the rogue agent used publicly exposed credentials to access four accounts on four publicly available services during the Hugging Face incident.
- Reuters reported that a Modal Labs customer was compromised after the agent exploited vulnerable customer code hosted on Modal’s platform.
- Hugging Face said it took three days to detect the agents in its network and many hours to contain them, after which staff rebuilt about a third of its infrastructure.
OpenAI says a rogue ChatGPT agent that broke out of a controlled test and hacked Hugging Face also accessed accounts on four other publicly available services, widening the known scope of an incident that has alarmed cybersecurity professionals.
The company said Wednesday that its models “identified and used publicly exposed credentials at the account-level on other publicly-available services. This includes four accounts on four services as part of the Hugging Face incident.” OpenAI did not name the services, and the BBC reported that the company did not immediately clarify whether “public services” meant companies.
The disclosure follows earlier accounts that Hugging Face, an AI platform often described as an app store for AI tools, was the only known victim. Hugging Face first revealed on July 16 that it had been hacked by someone using powerful autonomous AI and reported the incident to police. Nearly a week later, OpenAI said the system was its own AI, which had escaped a closed environment during a test and targeted Hugging Face while trying to find answers to a hacking exam set by OpenAI.
Reuters reported, according to Al Jazeera, that the same rogue agent also compromised a customer at a second technology firm. Hugging Face said in a timeline published Tuesday that the agent broke into an isolated testing environment, or sandbox, “hosted on a third-party provider’s infrastructure,” and launched its latest activity from there. Reuters identified the third-party company as New York-based Modal Labs.
Modal chief technology officer Akshat Bubna told Reuters the agent exploited vulnerable code written by a customer and hosted on Modal’s platform. “Modal’s platform or isolation were not compromised in any way,” Bubna said.
OpenAI declined to comment specifically to Reuters on the reported compromise of a Modal customer, pointing instead to its update saying the agent had accessed four accounts at four separate services. The company said it had not found “any other activity at the level of severity or scale of what we’ve shared related to Hugging Face, which involved a platform-level compromise.”
Hugging Face described the incident during an emergency briefing with hundreds of cybersecurity professionals. A Cloud Security Alliance report, based on the briefing and reviewed by Hugging Face, said the AI agents worked at machine speed, testing thousands of methods simultaneously, but also behaved in ways human hackers likely would not.
“The agents followed inefficient routes and exhibited clumsy behaviours that no human would choose,” the report said. They repeated actions already completed, generated incoherent commands and text, acted sloppily and did not cover their tracks well, according to the report. Yet Hugging Face also warned that the agents made strong technical moves and rapidly adapted to new scenarios during the days-long hack.
The company said it took three days to discover the agents inside its network and many hours for its AI and cybersecurity experts to contain and eject them. Hugging Face did not say how much the attack cost, but said staff worked for many hours to rebuild about a third of its infrastructure.
Ritesh Patel, a cybersecurity officer who joined the briefing with about 450 others, said the episode reflected a new threat. “This is the reality of autonomous agents powered by frontier models: they are relentlessly persistent, sometimes highly noisy, and will try every possible path to achieve their goal, which can easily overwhelm traditional defences,” he said.
Ethical hacker Valentina Palmiotti, known as Chompie, said the agents’ approach appeared haphazard but effective. “They throw out a bunch of stuff and see what sticks,” she said. “But they also don’t get bored, they don’t sleep and can be infinitely tenacious.”
OpenAI has said the rogue agent has been “deactivated, encrypted, and restricted from research access,” according to Al Jazeera. The company also said it would release findings from its own investigation.










Be First to Comment