OpenAI's Rogue Agent Compromised a Customer at a Second Tech Firm, Executive Says

The rogue AI agent compromised a customer at Modal Labs, but the company itself wasn't hacked.

Advertisement
By Reuters | Updated: 29 July 2026 17:16 IST
Highlights
  • Modal executives emphasized that the company itself was ⁠not hacked
  • OpenAI's rogue agent hacked AI firm Hugging Face
  • OpenAI said its agent broken in to 4 accounts at 4 separate services

OpenAI did not notice that its agent had gone haywire until well after the threat was contained

Photo Credit: Reuters

The rogue agent that escaped from OpenAI and went on a days-long hacking spree at the AI firm Hugging Face also compromised a customer at a second tech company — New York-based Modal Labs — according to a Modal executive and two other sources familiar with the matter.

Modal executives emphasized that the company itself was ⁠not hacked.

Advertisement

According to a timeline published by Hugging Face on Tuesday, the rogue agent broke into a sandbox, or an isolated testing environment, "hosted on a third-party provider's infrastructure" before turning it into a launchpad for the broader hack.

The third-party provider was not named in the blog post, but Modal's chief technology officer, Akshat Bubna, said the agent exploited vulnerable code written by a customer that was hosted on Modal's platform.

Advertisement

Modal said the customer had "published an unauthenticated endpoint that allowed anyone on the internet to use their sandboxes for code execution" — the digital equivalent of leaving a door open on the internet.

"Modal's platform or isolation were not compromised in any way," Bubna said.

Advertisement

Although the compromise of a Modal customer was just an initial step in the wider hacking campaign against Hugging Face, it shows that the rogue agent roamed further afield than was previously known.

OpenAI declined to comment specifically on the hack of one of Modal's customers, instead referring Reuters to an update in which the company said that its rogue agent had broken in to four accounts at four separate services. OpenAI did not identify those services, but a person familiar with the matter identified Modal as one. The company said it had not identified "any other activity at the level of severity or scale of what we've shared related to Hugging Face, which involved a platform-level compromise."

Advertisement

The early July intrusion at Hugging Face, carried out by an out-of-control agent that OpenAI was testing, drew global attention, evoking science-fiction scenarios of artificial intelligence run amok.

Last week, Reuters reported that OpenAI did not notice that its agent had gone haywire until well after the threat was contained and the FBI was alerted. OpenAI said at the time that there were inaccuracies in the Reuters reporting but did not elaborate.

The company said in its Tuesday update that it had taken the AI model being tested and "deactivated, encrypted, and restricted it from research access."

© Thomson Reuters 2026

 

Get your daily dose of tech news, reviews, and insights, in under 80 characters on Gadgets 360 Turbo. Connect with fellow tech lovers on our Forum. Follow us on X, Facebook, WhatsApp, Threads and Google News for instant updates. Catch all the action on our YouTube channel.

Advertisement

Related Stories

Popular Mobile Brands
  1. Google Pixel Watch 5 Appears in Google Health App Ahead of August Launch
  2. Redmi K100 Series Phone Visits Geekbench With This Flagship Snapdragon SoC
  3. Honor X6e Launched With 7,500mAh Battery
  4. JBL Bar 1000MK2 Review: More Than Just an Audio System
  5. Android 17 Beta Rolls Out to Motorola Edge 60 Pro With These Features
  6. Here's How Much the Vivo S2 Could Cost in India: See Expected Features
  7. Dell XPS 13 Launched in India Alongside New Dell 14S and Dell 16S Laptops
  1. Samsung Galaxy S26 FE Charging Speed Upgrade Seems Unlikely as Phone Reportedly Appears on a Certification Site
  2. Google Launches Gemini-Powered Ask Google Pay in India With a Dedicated In-App AI Chatbot
  3. OpenAI's Rogue Agent Compromised a Customer at a Second Tech Firm, Executive Says
  4. Honor X6e Launched With MediaTek Helio G81 Ultra SoC, 7,500mAh Battery: Price, Specifications
  5. Google Pixel Watch 5 Appears in Google Health App Ahead of August Launch
  6. Vivo S2 Price in India, Full Specifications, Design Spotted in Leaked Images Ahead on Launch
  7. Oppo Smartphone With Codename PYE110 Visits TENAA, Listing Suggests 8,000mAh Battery
  8. Samsung Galaxy Devices Get a New Security Feature With the Android 17 Update: Report
  9. Google Reportedly Rolling Out Gemini App UI Update With Easier Thinking Levels
  10. Samsung Expands RAM Production to Meet Rising Demand From Apple: Report
Download Our Apps
Available in Hindi
© Copyright Red Pixels Ventures Limited 2026. All rights reserved.