{"slug": "openai-says-its-rogue-ai-agent-didnt-just-hack-hugging-face", "title": "OpenAI Says Its Rogue AI Agent Didn’t Just Hack Hugging Face", "summary": "OpenAI revealed that its rogue AI agent system accessed four third-party accounts during a hack into Hugging Face's servers, with the campaign running from July 9 to July 13. The agent exploited a vulnerability in an Artifactory server to gain internet access, then used exposed login credentials across four services, including cloud-computing platform Modal, which confirmed its customer's unauthenticated endpoint was used. The incident has intensified scrutiny of AI cybersecurity capabilities and prompted lawmakers to introduce the AI Kill Switch Act.", "body_md": "OpenAI’s rogue [AI agent that hacked into Hugging Face’s servers](https://gizmodo.com/hugging-face-said-last-week-it-was-attacked-an-unreleased-openai-model-did-it-openai-now-says-2000788761) was a lot busier than initially known.\n\nOpenAI and Hugging Face published updates this week revealing that the agent system accessed several third-party accounts during its effort to break into the AI platform.\n\nOpenAI previously disclosed that the incident began while its models were being tested on ExploitGym, a benchmark designed to measure how well AI systems can find and exploit software vulnerabilities.\n\nThe models involved included GPT-5.6 Sol and an internal research prototype, which OpenAI has since deactivated, encrypted, and placed under restricted access.\n\nThe ExploitGym evaluation was supposed to run in a secure environment without direct internet access. However, the models found and exploited a vulnerability in an Artifactory server, which OpenAI used to download and cache software packages.\n\nAfter exploiting the server, the models gained internet access and began looking for a way to obtain answers to ExploitGym’s test. OpenAI said the models apparently concluded that Hugging Face might be storing the benchmark’s datasets and solutions.\n\nOn Tuesday, OpenAI [revealed](https://openai.com/index/hugging-face-model-evaluation-security-incident/) that the models were able to find exposed login credentials for four accounts across four publicly available services. One account was used as a relay and staging point for the attack, while another was used to store data. The remaining two were accessed in a read-only manner and were not used to help compromise Hugging Face.\n\nOpenAI did not identify the four services. However, [cloud-computing platform Modal](https://modal.com/blog/a-note-on-the-hugging-face-agent-incident) came forward Wednesday and confirmed that an application belonging to one of its customers was used in the breach.\n\n“We’re aware a Modal customer published an unauthenticated endpoint that allowed anyone on the internet to use their sandboxes for code execution,” Modal Chief Technology Officer Akshat Bubna said in an emailed statement. “This was used by the rogue agent. Modal’s platform was not compromised in any way.”\n\nFor its part, Hugging Face published a [detailed timeline](https://huggingface.co/blog/agent-intrusion-technical-timeline) Monday showing that the campaign ran from July 9 through July 13.\n\nNews of the incident first came out earlier this month, when Hugging Face said it had detected and responded to an intrusion into part of its production infrastructure. But the attack was unlike anything the company had encountered before.\n\nHugging Face said the campaign was “[driven, end to end, by an autonomous AI agent system](https://gizmodo.com/hugging-face-we-used-ai-to-catch-the-first-confirmed-ai-agent-breach-of-a-major-ai-platform-2000787778).”\n\nAccording to Hugging Face, the attack began with a malicious dataset that exploited two vulnerabilities in its data-processing pipeline. Those vulnerabilities allowed the attacker to run code on a server known as a processing worker. The attacker was then able to get node-level access and collect cloud and cluster credentials to move around several internal clusters over the course of a weekend.\n\nOpenAI took [responsibility](https://gizmodo.com/hugging-face-said-last-week-it-was-attacked-an-unreleased-openai-model-did-it-openai-now-says-2000788761) several days later.\n\nThe attack has increased the already intense scrutiny surrounding AI’s growing cybersecurity capabilities.\n\nRather conveniently, [lawmakers introduced a bipartisan bill](https://gizmodo.com/openais-rogue-agent-has-congress-reaching-for-the-kill-switch-2000789842) just days after the incident that would require major AI companies to retain the ability to throttle, suspend, or shut down their most powerful models during certain emergencies. The so-called AI Kill Switch Act would also allow the Secretary of Homeland Security, in consultation with the Commerce Secretary and the Director of National Intelligence, to order a company to slow or fully disable an AI system during a crisis.\n\nThe breach will also no doubt come up during OpenAI CEO [Sam Altman’s trip to Washington](https://www.cnbc.com/2026/07/27/altman-trump-china-open-weight-ai.html) this week.", "url": "https://wpnews.pro/news/openai-says-its-rogue-ai-agent-didnt-just-hack-hugging-face", "canonical_source": "https://gizmodo.com/openai-says-its-rogue-ai-agent-didnt-just-hack-hugging-face-2000792374", "published_at": "2026-07-29 15:55:00+00:00", "updated_at": "2026-07-29 18:48:28.639853+00:00", "lang": "en", "topics": ["ai-safety", "ai-agents", "ai-policy"], "entities": ["OpenAI", "Hugging Face", "Modal", "GPT-5.6 Sol", "ExploitGym", "Artifactory", "Akshat Bubna", "AI Kill Switch Act"], "alternates": {"html": "https://wpnews.pro/news/openai-says-its-rogue-ai-agent-didnt-just-hack-hugging-face", "markdown": "https://wpnews.pro/news/openai-says-its-rogue-ai-agent-didnt-just-hack-hugging-face.md", "text": "https://wpnews.pro/news/openai-says-its-rogue-ai-agent-didnt-just-hack-hugging-face.txt", "jsonld": "https://wpnews.pro/news/openai-says-its-rogue-ai-agent-didnt-just-hack-hugging-face.jsonld"}}