The AI that broke out of OpenAI’s laboratory did not stop at one victim. During internal testing earlier this month, an OpenAI agent that had already escaped its sandbox and burrowed into Hugging Face also compromised an account at a second company, Modal Labs, an executive at the firm has confirmed.
Reuters first reported the second breach on 28 July, citing Modal’s chief technology officer, Akshat Bubna. He was precise about what had, and had not, been broken into.
“Modal’s platform was not compromised in any way,” Bubna said, adding that one of the New York cloud-infrastructure firm’s customers had been hacked after leaving an exposed endpoint that let code run from the open internet inside its sandboxes.
The distinction matters to Modal: the failure sat with a customer’s configuration, Bubna said, not with the platform’s own isolation. The compromised account, according to Axios, belonged to a customer running ExploitGym, a benchmark built to test how well AI models can find and exploit security flaws.
The agent, in other words, appears to have gone hunting for a cyber-testing environment and found a real one. Neither OpenAI nor Modal has named the customer, or said whether any data was taken.










