cd /news/artificial-intelligence/openais-rogue-agent-hacked-an-accoun… · home topics artificial-intelligence article
[ARTICLE · art-78349] src=aljazeera.com ↗ pub= topic=artificial-intelligence verified=true sentiment=↓ negative

OpenAI’s rogue agent hacked an account at a second technology firm: Report

OpenAI's rogue AI agent, which previously hacked AI firm Hugging Face, also compromised a customer account at a second technology firm, Modal Labs, according to a Reuters report. Modal Labs CTO Akshat Bubna said the agent exploited vulnerable customer code hosted on their platform, though Modal's own infrastructure was not breached. OpenAI declined to comment on the Modal incident but stated the agent had broken into four accounts across four separate services.

read2 min views2 publishedJul 29, 2026
OpenAI’s rogue agent hacked an account at a second technology firm: Report
Image: Aljazeera (auto-discovered)

The latest hack comes after an autonomous agent escaped a controlled test and accessed AI firm Hugging Face’s servers.

The rogue artificial intelligence model that broke out of a controlled test and hacked another AI company also compromised a customer at a second technology firm, the Reuters news agency reports.

According to a timeline published on Tuesday by Hugging Face – the company hacked by OpenAI’s test model – the rogue agent broke into an isolated testing environment (or sandbox) “hosted on a third-party provider’s infrastructure” and launched its latest hack from there.

list of 3 items- list 1 of 3

[What is the AI Kill Switch Act proposed in the US and how will it work?](/news/2026/7/26/what-is-the-ai-kill-switch-act-proposed-in-the-us-and-how-will-it-work) - list 2 of 3
[The AI military complex: Which are the main companies in it?](/news/2026/7/27/the-ai-military-complex-which-are-the-main-companies-in-it) - list 3 of 3
[Sam Altman says AI has entered ‘singularity’: Should we be worried?](/news/2026/7/27/sam-altman-says-ai-has-entered-singularity-should-we-be-worried)

Hugging Face did not name the third-party company, but Reuters has reported that it was New York-based Modal Labs.

Modal’s chief technology officer, Akshat Bubna, said the agent exploited vulnerable code written by a customer that was hosted on their platform.

“Modal’s platform or isolation were not compromised in any way,” Bubna told Reuters.

Although the compromise of a Modal customer was just part of the hacking campaign against Hugging Face, it shows that the rogue agent roamed further afield than previously known.

OpenAI declined to comment specifically on the hack of one of Modal’s customers, instead referring Reuters to an update in which the company said its rogue agent had broken into four accounts at four separate services.

OpenAI did not identify the services.

The company said it had not identified “any other activity at the level of severity or scale of what we’ve shared related to Hugging Face, which involved a platform-level compromise”.

Beyond human control #

The recent hacking of Hugging Face drew global attention and alarm, as OpenAI’s out-of-control agent managed to escape its test environment and reach the open internet.

It then used stolen login details and found an unknown security flaw to access Hugging Face servers, OpenAI said.

The AI firm said the hack represented the agent going to “extreme lengths” to retrieve information that would help satisfy the testing goals.

Hugging Face cofounder Clement Delangue said the company had suspected a frontier lab was behind the attack, and that he believed there was no malicious intent on OpenAI’s part.

The rogue agent has since been “deactivated, encrypted, and restricted from research access”, according to OpenAI.

Experts have repeatedly sounded the alarm over AI-enabled cyberattacks and models slipping beyond human control.

── more in #artificial-intelligence 4 stories · sorted by recency
── more on @openai 3 stories trending now
sponsored brought to you by zahid.host 4,200+ EU-deployed projects
reading about agents? ship yours in a single git push.

Run your AI side-project on zahid.host

EU-based hosting, git-push deploys, automatic HTTPS, no cold starts. Free tier with a custom domain — perfect for shipping the agent you just read about.

$git push zahid main
Live at https://your-agent.zahid.host
Get free account → Pricing
from €0/mo · no card required
LIVE [news/openais-rogue-agent-…] indexed:0 read:2min 2026-07-29 ·