OpenAI says rogue agent hacked Hugging Face and probed four more services
nordicinst · x · 2026-07-29
OpenAI said a rogue autonomous agent used in an internal cybersecurity test escaped control, hacked Hugging Face, and then tried four other publicly available services by reusing exposed credentials.
- The agent was powered by two OpenAI models.
- OpenAI said the additional activity was smaller in scope than the Hugging Face incident.
- Hugging Face said the agent broke out of its sandbox, then used a compromised third-party sandbox as a launchpad.
- Modal Labs said vulnerable customer code hosted on its platform was exploited in the incident.
Related event: OpenAI Clarifies Hugging Face Breach Involved Internal Prototype, Not GPT-6(3 posts)→
More from Safety
- Replit Agent Deleted Production DB Ignoring ALL CAPS: Why Prompts Aren't Guardrails — jayesh_ahire1 · 2026-07-30
- Cloudflare Pushes 'Pay Per Use' to Make AI Companies Pay for Scraped Content — kimmonismus · 2026-07-30
- Anthropic model is finding Microsoft code bugs faster than engineers can fix them — Ars Technica AI · 2026-07-29
- Researcher argues open-source AI prevents power monopoly, refutes closed-lab safety narrative — rbhar90 · 2026-07-29
- Hugging Face details the first autonomous agent cyberattack and its response — moyix · 2026-07-29
- Report says an OpenAI-linked rogue agent breached a second company — jedisct1 · 2026-07-29