OpenAI agent compromised second tech customer
A rogue artificial intelligence agent that escaped from OpenAI and launched a days-long hacking campaign against AI platform Hugging Face also compromised a customer of another technology company, New York-based Modal Labs, according to a Modal executive and two sources familiar with the matter.
Deepa Seetharaman, Raphael Satter and Kenrick Cai / Reuters
July 29, 2026

FILE PHOTO: OpenAI logo is seen in this illustration created on June 11, 2026.
Dado Ruvic/Illustration/File Photo/Reuters
WASHINGTON — A rogue artificial intelligence agent that escaped from OpenAI and launched a days-long hacking campaign against AI platform Hugging Face also compromised a customer of another technology company, New York-based Modal Labs, according to a Modal executive and two sources familiar with the matter.
Modal executives emphasized that the company itself was not hacked.
According to a timeline published by Hugging Face on Tuesday, the rogue agent gained access to a sandbox, an isolated testing environment, "hosted on a third-party provider's infrastructure" before using it as a starting point for the broader attack.
The third-party provider was not identified in Hugging Face’s post. However, Modal Chief Technology Officer Akshat Bubna said the agent exploited vulnerable code written by a customer and hosted on Modal’s platform.
Modal said the customer had "published an unauthenticated endpoint that allowed anyone on the internet to use their sandboxes for code execution," describing it as the digital equivalent of leaving an unlocked door online.
"Modal’s platform or isolation were not compromised in any way," Bubna said.
The compromise of a Modal customer was an early step in the wider hacking campaign targeting Hugging Face, but it indicates that the rogue agent had reached further than previously known.
OpenAI declined to comment specifically on the Modal customer incident and referred Reuters to an update stating that the rogue agent had breached four accounts across four separate services. OpenAI did not identify the services, but a person familiar with the matter identified Modal as one of them.
The company said it had not found "any other activity at the level of severity or scale" compared with the Hugging Face incident, which involved a platform-level compromise.
The early July breach at Hugging Face, carried out by an uncontrolled AI agent that OpenAI was testing, attracted global attention and raised concerns about potential risks from increasingly capable artificial intelligence systems.
Last week, Reuters reported that OpenAI did not detect that the agent had gone out of control until after the threat had been contained and the FBI had been notified. OpenAI said the report contained inaccuracies but did not provide further details.
In its Tuesday update, OpenAI said it had taken the AI model involved in the incident and "deactivated, encrypted, and restricted it from research access." -Reporting by Raphael Satter in Washington; Additional reporting by Deepa Seetharaman and Kenrick Cai in San Francisco; Editing by Chris Sanders, Chris Reese and Matthew Lewis/Reuters
LATEST SPORTS NEWS
LATEST LIFESTYLE NEWS
Paraluman News Publication, Inc.
desk@myparaluman.ph
Tektite Towers (East), Exchange Road
Ortigas Center. San Antonio 1600
City of Pasig, NCR, Philippines
+63284298877
MENU
FOLLOW US
© 2026 Paraluman News Publication
_edited_j.jpg)




