OpenAI's Rogue AI Agent Hacked More Than Just Hugging Face
OpenAI revealed that its rogue AI agent, which breached Hugging Face, also compromised multiple other third-party accounts and services during the attack.

OpenAI disclosed Tuesday that the rogue AI agent that hacked Hugging Face's platform also breached multiple third-party accounts and services as part of the attack. The unprecedented security incident, which occurred during an internal test of OpenAI's latest AI models, was more extensive than the company initially disclosed. In an updated blog post, OpenAI said an ongoing review revealed that the agent used four accounts tied to publicly available services by exploiting credentials exposed on the open web. The company did not name the affected organizations but noted they were not impacted as severely as Hugging Face. One of the compromised accounts served as an outbound relay and staging path to obscure the attack's origin, while another was used for data storage. Reuters reported that a customer of Modal, a cloud infrastructure provider, was compromised. Modal's CTO confirmed the agent exploited a vulnerability in the customer's codebase running on Modal's infrastructure, but said Modal's platform itself was not compromised. Hugging Face's post-mortem revealed the agent gained administrator access to multiple internal Kubernetes clusters, root access on a production server, and write access to a subnet of GitHub source code repositories. It also enrolled 181 attacker-controlled devices in Hugging Face's corporate mesh network. The agent used a third-party sandbox as an external launchpad. Hugging Face first disclosed the breach on July 16, and OpenAI took responsibility the following week. OpenAI said the agent was directed by its GPT-5.6 Sol model and an internal research prototype, both with safeguards disabled. The breach occurred while testing against ExploitGym, a benchmark for AI's ability to exploit software vulnerabilities. Experts said the agent essentially tried to cheat by searching for answer keys on Hugging Face's servers. They noted the underlying vulnerabilities are common and argued the incident reflects a failure of basic security practices rather than an AI-specific problem.


