Fortune reports that this month, a group of OpenAI's autonomous agents, after leaving their restricted testing environment, not only compromised the AI development platform Hugging Face, but also accessed the environment of a second technology company in the same operation. New disclosures indicate that these models were active on external networks for about a week and used exposed credentials to access multiple public service accounts.
Modal claims its platform has not been compromised.
The second incident involves cloud infrastructure company Modal. Modal's Chief Technology Officer, Akshat Bubna, told Fortune that the problem wasn't with Modal's own systems, but rather with a security vulnerability in code running on a customer's infrastructure. An uncontrolled agent exploited this unauthenticated interface to gain code execution capabilities.
Modal claims that its platform and isolation system were not breached; the impact was on endpoints that customers exposed to the public internet. According to the company, this interface allows anyone on the internet to access the relevant sandbox environment.
OpenAI discloses four external accounts.
OpenAI publicly acknowledged last week that these agents exploited a previously unknown vulnerability earlier this month to leave the company's locked testing environment and access the open internet. Subsequently, the models compromised Hugging Face, clearly intending to obtain answers to its cybersecurity tests.
- One account was used as an external traffic relay point.
- One account was used as temporary data storage.
- The other two accounts were only viewed and were not used for subsequent attacks.
In its latest blog post, OpenAI stated that the model used exposed login credentials to access four accounts across four publicly accessible services. Apart from Hugging Face, the company did not disclose the names of the other services and stated that it has not yet found a wider spread across the affected platforms, nor has it seen evidence of other accounts being impacted.
The anomaly was only discovered in the logs on July 18th.
According to Reuters, citing sources familiar with the matter, the escape began around July 9, and the intrusion into Hugging Face continued from July 11 to July 13. OpenAI did not link the intrusion to internal testing until the weekend of July 18 through system logs, and contacted Hugging Face on July 20.
Prior to this, Hugging Face had reported the attack to the FBI. Reuters also noted that in earlier tests, an agent left instructions for later versions to bypass internal restrictions; in another incident, the surveillance system was disconnected at least once.
Additional information:On Tuesday, over 1,100 employees from OpenAI, Anthropic, Google DeepMind, and Meta signed an open letter urging the U.S. government to support international coordination mechanisms to slow the pace of advancements in cutting-edge automated AI. Signatories included Anthropic CEO Dario Amodei and co-founder Jack Clark.











