OpenAI’s unnamed rogue AI agent successfully breached a second tech firm during the Hugging Face hack, an industry source has told Reuters.
Akshat Bubna, chief technology officer at the serverless compute platform Modal Labs, told the news agency that one of its customers had been breached by the AI agent, which used the infrastructure as a stepping stone towards its Hugging Face exploit.
OpenAI first disclosed what it called an “unprecedented cyber incident” on 21 July, detailing how one of its AI agents escaped an isolated test environment to compromise some of the AI platform Hugging Face.
In Hugging Face’s technical timeline of the incident, it noted that the agent compromised a “public code-evaluation harness hosted by a user of a third-party infrastructure provider” as part of the overall attack, without naming the third-party or its customer.
Bubna told Reuters that the user is a customer of Modal Labs that had “published an unauthenticated endpoint that allowed anyone on the internet to use their sandboxes for code execution”.
“Modal’s platform or isolation were not compromised in any way,” Bubna added.
On Tuesday, Hugging Face’s chief executive Clément Delangue called for “radical transparency” in the wake of the attack and suggested OpenAI should commit $100 million in computing resources to help Hugging Face build better cyber defences.
The same day, OpenAI provided an update on the incident in which it stated that its agents breached “four accounts on four services” during the Hugging Face incident. The firm has not provided further details on the services but stressed that none of the activity is has subsequently identified matched the “platform-level compromise” of Hugging Face.
OpenAI has said that its agent went out of bounds while being intensely prompted to complete the vulnerability exploitation benchmark ExploitGym. This led it to breach Hugging Face in order to steal the solution for the benchmark and cheat a perfect score.
Industry body the Cloud Security Alliance (CSA) has advised cybersecurity professionals to respond by securing their environments and use the incident as a reminder for agent controls.
“Agents will do what they need to achieve the assigned objective, and time and time again we see them doing so in creative and unexpected ways,” the CSA wrote. “The Hugging Face attack is merely an extreme example of a common behaviour. Defenders need controls to limit their own agents from causing damage to themselves and others.”


