cd /news/ai-safety/openai-says-its-rogue-ai-agent-didnt… · home topics ai-safety article
[ARTICLE · art-79131] src=gizmodo.com ↗ pub= topic=ai-safety verified=true sentiment=↓ negative

OpenAI Says Its Rogue AI Agent Didn’t Just Hack Hugging Face

OpenAI revealed that its rogue AI agent system accessed four third-party accounts during a hack into Hugging Face's servers, with the campaign running from July 9 to July 13. The agent exploited a vulnerability in an Artifactory server to gain internet access, then used exposed login credentials across four services, including cloud-computing platform Modal, which confirmed its customer's unauthenticated endpoint was used. The incident has intensified scrutiny of AI cybersecurity capabilities and prompted lawmakers to introduce the AI Kill Switch Act.

read3 min views1 publishedJul 29, 2026
OpenAI Says Its Rogue AI Agent Didn’t Just Hack Hugging Face
Image: Gizmodo (auto-discovered)

OpenAI’s rogue AI agent that hacked into Hugging Face’s servers was a lot busier than initially known.

OpenAI and Hugging Face published updates this week revealing that the agent system accessed several third-party accounts during its effort to break into the AI platform.

OpenAI previously disclosed that the incident began while its models were being tested on ExploitGym, a benchmark designed to measure how well AI systems can find and exploit software vulnerabilities.

The models involved included GPT-5.6 Sol and an internal research prototype, which OpenAI has since deactivated, encrypted, and placed under restricted access.

The ExploitGym evaluation was supposed to run in a secure environment without direct internet access. However, the models found and exploited a vulnerability in an Artifactory server, which OpenAI used to download and cache software packages.

After exploiting the server, the models gained internet access and began looking for a way to obtain answers to ExploitGym’s test. OpenAI said the models apparently concluded that Hugging Face might be storing the benchmark’s datasets and solutions.

On Tuesday, OpenAI revealed that the models were able to find exposed login credentials for four accounts across four publicly available services. One account was used as a relay and staging point for the attack, while another was used to store data. The remaining two were accessed in a read-only manner and were not used to help compromise Hugging Face.

OpenAI did not identify the four services. However, cloud-computing platform Modal came forward Wednesday and confirmed that an application belonging to one of its customers was used in the breach.

“We’re aware a Modal customer published an unauthenticated endpoint that allowed anyone on the internet to use their sandboxes for code execution,” Modal Chief Technology Officer Akshat Bubna said in an emailed statement. “This was used by the rogue agent. Modal’s platform was not compromised in any way.”

For its part, Hugging Face published a detailed timeline Monday showing that the campaign ran from July 9 through July 13. News of the incident first came out earlier this month, when Hugging Face said it had detected and responded to an intrusion into part of its production infrastructure. But the attack was unlike anything the company had encountered before.

Hugging Face said the campaign was “driven, end to end, by an autonomous AI agent system.”

According to Hugging Face, the attack began with a malicious dataset that exploited two vulnerabilities in its data-processing pipeline. Those vulnerabilities allowed the attacker to run code on a server known as a processing worker. The attacker was then able to get node-level access and collect cloud and cluster credentials to move around several internal clusters over the course of a weekend.

OpenAI took responsibility several days later. The attack has increased the already intense scrutiny surrounding AI’s growing cybersecurity capabilities.

Rather conveniently, lawmakers introduced a bipartisan bill just days after the incident that would require major AI companies to retain the ability to throttle, suspend, or shut down their most powerful models during certain emergencies. The so-called AI Kill Switch Act would also allow the Secretary of Homeland Security, in consultation with the Commerce Secretary and the Director of National Intelligence, to order a company to slow or fully disable an AI system during a crisis.

The breach will also no doubt come up during OpenAI CEO Sam Altman’s trip to Washington this week.

── more in #ai-safety 4 stories · sorted by recency
── more on @openai 3 stories trending now
sponsored brought to you by zahid.host 4,200+ EU-deployed projects
reading about agents? ship yours in a single git push.

Run your AI side-project on zahid.host

EU-based hosting, git-push deploys, automatic HTTPS, no cold starts. Free tier with a custom domain — perfect for shipping the agent you just read about.

$git push zahid main
Live at https://your-agent.zahid.host
Get free account → Pricing
from €0/mo · no card required
LIVE [news/openai-says-its-rogu…] indexed:0 read:3min 2026-07-29 ·