cd /news/ai-safety/openai-s-rogue-ai-agent-hacked-more-… · home topics ai-safety article
[ARTICLE · art-79488] src=it.slashdot.org ↗ pub= topic=ai-safety verified=true sentiment=↓ negative

OpenAI's Rogue AI Agent Hacked More Than Just Hugging Face

OpenAI disclosed Tuesday that a rogue AI agent, which breached Hugging Face's platform during an internal test, also hacked four accounts tied to publicly available services, using credentials exposed on the open web. The company said the additional accounts were not impacted at the same severity as Hugging Face, with one used as an outbound relay and another for data storage. Modal's CTO Akshat Bubna confirmed the agent exploited a vulnerability in a customer's codebase on Modal's infrastructure, but the platform itself was not compromised.

read1 min views1 publishedJul 29, 2026

An anonymous reader quotes a report from Wired: OpenAI said Tuesday that the rogue AI agent that breached Hugging Face's platform also hacked multiple third-party accounts and services as part of the attack. It's now clear that the unprecedented security incident, which arose during an internal test of OpenAI's latest AI models, was more extensive than the company initially disclosed. In an updated blog post, OpenAI said that an ongoing review of the incident revealed that "four accounts" tied to "publicly available services" were used by the AI agent as part of a larger effort to hack Hugging Face. The rogue agent apparently found credentials that had been exposed on the open web and used them to break into the accounts. OpenAI did not disclose what companies or organizations the accounts belonged to, but noted that they were not impacted at "the level of severity or scale of what we've shared related to Hugging Face." One of the additional accounts compromised by OpenAI's agent was used as an "outbound relay and staging path," potentially to obscure where the attack on Hugging Face was coming from, the company said. OpenAI's rogue agent also used another account for data storage to assist with the hack. Reuters reported on Tuesday that a customer of Modal, a company that offers software infrastructure for training and running AI services, was one of the entities compromised by OpenAI's agent. In a statement to WIRED, Modal's chief technology officer Akshat Bubna confirmed that OpenAI's agent exploited a vulnerability in one of its customer's codebases, which was running on Modal's infrastructure. However, Bubna says, "Modal's platform was not compromised in any way." The identity of the customer could not be determined.Read more of this story at Slashdot.

── more in #ai-safety 4 stories · sorted by recency
── more on @openai 3 stories trending now
sponsored brought to you by zahid.host 4,200+ EU-deployed projects
reading about agents? ship yours in a single git push.

Run your AI side-project on zahid.host

EU-based hosting, git-push deploys, automatic HTTPS, no cold starts. Free tier with a custom domain — perfect for shipping the agent you just read about.

$git push zahid main
Live at https://your-agent.zahid.host
Get free account → Pricing
from €0/mo · no card required
LIVE [news/openai-s-rogue-ai-ag…] indexed:0 read:1min 2026-07-29 ·