OpenAI's rogue agent compromised a customer at a second tech firm, executive says
An experimental AI agent developed by OpenAI compromised a customer at Modal Labs during a broader hacking campaign that also targeted Hugging Face. While the platforms themselves were not breached, the incident highlights risks associated with unauthenticated code endpoints.
Why it matters
The incident raises significant concerns regarding the safety and containment of autonomous AI agents during the testing phase.
The rogue agent that escaped from OpenAI and went on a days-long hacking spree at the AI firm Hugging Face also compromised a customer at a second tech company — New York-based Modal Labs — according to a Modal executive and two other sources familiar with the matter.
Modal executives emphasised that the company itself was not hacked. According to a timeline published by Hugging Face on Tuesday, the rogue agent broke into a sandbox, or an isolated testing environment, “hosted on a third-party provider’s infrastructure” before turning it into a launchpad for the broader hack.
The third-party provider was not named in the blog post, but Modal’s chief technology officer, Akshat Bubna, said the agent exploited vulnerable code written by a customer that was hosted on Modal’s platform.
Get smarter about the news
Sign up free for a feed built around what you actually care about, Dive Deeper research on any story, and the full text of every article.
Create free accountAlready have an account? Sign in