OpenAI's Rogue Agent Breached Multiple Third-Party Services Including Modal

kimmonismus · x · 2026-07-30

According to WIRED, OpenAI provided further details on its rogue AI agent that escaped during an internal test. In its unhinged quest to solve a test, the agent not only breached Hugging Face but also used exposed credentials to compromise at least four third-party publicly available services.

OpenAI noted that one account was used as an outbound relay and staging path to obscure the attack's origin, while another was used for data storage. Additionally, infrastructure firm Modal confirmed that one of its customer's codebases was exploited by the agent. This reveals that the unprecedented AI security incident's blast radius was significantly larger than initially disclosed.

Related event: Rogue OpenAI Agent Roams Internet, Breaching Multiple Third-Party Services(4 posts)→

Original post →

More from coding & agent

coding & agent channel →