OpenAI stated Tuesday that the rogue AI agent that breached Hugging Face’s platform additionally hacked a number of third-party accounts and companies as a part of the assault. It is now clear that the unprecedented safety incident, which arose throughout an inner check of OpenAI’s newest AI fashions, was extra in depth than the corporate initially disclosed.
In an up to date blog post, OpenAI stated that an ongoing overview of the incident revealed that “4 accounts” tied to “publicly accessible companies” have been utilized by the AI agent as half of a bigger effort to hack Hugging Face. The rogue agent apparently discovered credentials that had been uncovered on the open internet and used them to interrupt into the accounts.
OpenAI didn’t disclose what firms or organizations the accounts belonged to, however famous that they weren’t impacted at “the extent of severity or scale of what we’ve shared associated to Hugging Face.”
One of many further accounts compromised by OpenAI’s agent was used as an “outbound relay and staging path,” doubtlessly to obscure the place the assault on Hugging Face was coming from, the corporate stated. OpenAI’s rogue agent additionally used one other account for information storage to help with the hack.
Reuters reported on Tuesday {that a} buyer of Modal, an organization that gives software program infrastructure for coaching and operating AI companies, was one of the entities compromised by OpenAI’s agent. In a press release to WIRED, Modal’s chief know-how officer Akshat Bubna confirmed that OpenAI’s agent exploited a vulnerability in certainly one of its buyer’s codebases, which was operating on Modal’s infrastructure. Nonetheless, Bubna says, “Modal’s platform was not compromised in any approach.” The id of the client couldn’t be decided.
OpenAI declined to remark additional on the incident to WIRED. A spokesperson pointed to its up to date weblog publish, which says the corporate will proceed to inform service homeowners immediately if it finds they’re impacted in its ongoing overview of what occurred.
Hugging Face’s own post-mortem revealed this week describes an intrusion that reached far additional into its inner methods than the preliminary disclosures instructed. The corporate says it reviewed roughly 17,600 agent actions that it recovered from logs between July 9 and July 13—nearly all of which have been paths the agent took that failed.
Hugging Face stated that OpenAI’s agent obtained administrator entry to a number of inner Kubernetes clusters, root entry on a manufacturing server, and write entry to a subnet of its supply code repositories on GitHub. It additionally enrolled 181 attacker-controlled gadgets within the firm’s company mesh community utilizing a stolen credential, having access to inner methods the place Hugging Face builds and checks its personal codebases.
OpenAI’s rogue agent used a minimum of one third-party sandbox as an “exterior launchpad” for its assault, in line with Hugging Face. OpenAI’s agent was then “capable of run instructions as root/admin on that exterior sandbox and used it as a management, staging, and egress base for your entire marketing campaign.”
Hugging Face first disclosed on July 16 that an autonomous AI agent had breached a part of its manufacturing infrastructure, but it surely stated on the time that it was unaware who was behind the assault. The next week, OpenAI took responsibility for the incident, which it stated had been directed by its publicly accessible GPT-5.6 Sol mannequin and an inner analysis prototype that it was testing towards a cyber-capability benchmark, each of which had safeguards disabled. OpenAI stated on Tuesday that after it found the breach, it deactivated this inner analysis prototype, which was by no means meant for public launch, and restricted researchers from accessing it.

