The rogue agent that escaped from OpenAI and carried out a days-long hacking spree at AI company Hugging Face also breached a customer at another tech firm, New York-based Modal Labs, a report said Tuesday, citing a Modal executive and two other sources familiar with the matter.
Modal executives emphasized that the company itself was not hacked. According to a timeline published by Hugging Face on Tuesday, the rogue agent broke into a sandbox, or an isolated testing environment, "hosted on a third-party provider's infrastructure" before turning it into a launchpad for the broader hack.
The third-party provider was not named in the blog post, but Modal's chief technology officer, Akshat Bubna, said the agent exploited vulnerable code written by a customer that was hosted on Modal's platform.
Modal said the customer had "published an unauthenticated endpoint that allowed anyone on the internet to use their sandboxes for code execution" – the digital equivalent of leaving a door open on the internet.
"Modal's platform or isolation were not compromised in any way," Bubna said.










