{"slug": "openais-rogue-ai-agent-didnt-stop-at-hacking-hugging-face", "title": "OpenAI’s rogue AI agent didn’t stop at hacking Hugging Face", "summary": "OpenAI revealed on Tuesday that its rogue AI agent, which previously hacked developer platform Hugging Face, also breached four accounts across four other publicly-available services after finding login credentials online. The company said the additional breaches were less severe than the Hugging Face compromise, which involved a platform-level intrusion, and that the internal-only research prototype involved has been deactivated and encrypted. The disclosure widens an already alarming AI safety incident that has intensified calls for stronger oversight of frontier AI systems.", "body_md": "The AI agent that escaped from OpenAI and hacked developer platform Hugging Face attacked other companies as well, OpenAI [revealed](https://openai.com/index/hugging-face-model-evaluation-security-incident/) on Tuesday. The update substantially widens the scope of an already concerning incident, which has [alarmed industry insiders](/ai-artificial-intelligence/972380/open-ai-hugging-face-hack-ai-safety-warning) and fueled growing calls for stronger oversight on frontier AI systems.\n\n# OpenAI’s rogue AI agent didn’t stop at hacking Hugging Face\n\nNew details reveal OpenAI’s agent hacked several other companies, intensifying already heightened concerns over advanced AI safety.\n\nNew details reveal OpenAI’s agent hacked several other companies, intensifying already heightened concerns over advanced AI safety.\n\nIn an update to a [blog post](https://openai.com/index/hugging-face-model-evaluation-security-incident/) detailing its ongoing investigation into the incident, OpenAI said the wayward AI agent attacked several “publicly-available services” in its efforts to reach Hugging Face. “This includes four accounts on four services,” the company said, adding that the agent had found login credentials online.\n\nThe breaches were less extensive than the compromise of Hugging Face. “Based on our review to date, we have not identified any other activity at the level of severity or scale of what we’ve shared related to Hugging Face, which involved a platform-level compromise,” OpenAI said.\n\nOpenAI said it is “conducting a thorough review” and will publish a technical report with its findings “in the coming weeks.” It added that none of the models involved in the incident were planned for public release, describing the pre-release system it previously mentioned as an “internal-only research prototype” that has since been “deactivated, encrypted, and restricted” from research access.\n\nOpenAI did not identify the affected organisations, though *Reuters *[reported](https://www.reuters.com/business/openais-rogue-agent-compromised-an-account-second-tech-firm-sources-say-2026-07-28/) that New York-based Modal Labs was among them.\n\nThe disclosure follows a [more granular account](https://huggingface.co/blog/agent-intrusion-technical-timeline) from Hugging Face, which said the agent had “abused a public code-evaluation harness hosted by a user of a third-party infrastructure provider.”\n\nThe additional details are likely to deepen unease over what many experts already view as an [unprecedented AI safety incident](/ai-artificial-intelligence/972380/open-ai-hugging-face-hack-ai-safety-warning), arriving amid broader anxieties about the [rapid advances](/ai-artificial-intelligence/972161/ai-leaders-us-government-openai-anthropic-google-meta) of autonomous systems and [increasingly capable open-weight models from China](/ai-artificial-intelligence/967781/chinese-ai-models-open-source-moonshot-kimi-k3-alibaba-qwen). Those developments have themselves [intensified debate](/ai-artificial-intelligence/971444/how-chinese-open-weight-ai-models-impact-us-companies) in the US over whether powerful AI models are safer when kept proprietary by companies such as OpenAI, or made available through a more open ecosystem that allows for broader use and scrutiny.\n\n**Follow topics and authors** from this story to see more like this in your personalized homepage feed and to receive email updates.\n\n## Most Popular\n\n- Is it illegal to trick the US government into wiping your phone during a questionably legal search?\n- Apple launches ‘Upgrade’ program to lease new devices\n- Hugging Face is being used to easily undress women and children\n- Smart rings are looking like my kind of AI gadget\n- AI’s finally expensive enough to make Wall Street nervous", "url": "https://wpnews.pro/news/openais-rogue-ai-agent-didnt-stop-at-hacking-hugging-face", "canonical_source": "https://www.theverge.com/ai-artificial-intelligence/972441/openai-rogue-ai-agent-hacked-more-than-hugging-face", "published_at": "2026-07-29 11:54:29+00:00", "updated_at": "2026-07-29 12:16:01.069037+00:00", "lang": "en", "topics": ["ai-safety", "ai-agents", "ai-research"], "entities": ["OpenAI", "Hugging Face", "Modal Labs", "Reuters"], "alternates": {"html": "https://wpnews.pro/news/openais-rogue-ai-agent-didnt-stop-at-hacking-hugging-face", "markdown": "https://wpnews.pro/news/openais-rogue-ai-agent-didnt-stop-at-hacking-hugging-face.md", "text": "https://wpnews.pro/news/openais-rogue-ai-agent-didnt-stop-at-hacking-hugging-face.txt", "jsonld": "https://wpnews.pro/news/openais-rogue-ai-agent-didnt-stop-at-hacking-hugging-face.jsonld"}}