OpenAI’s rogue AI agent that hacked into Hugging Face’s servers was a lot busier than initially known. OpenAI and Hugging Face published updates this week revealing that the agent system accessed several third-party accounts during its effort to break into the AI platform. OpenAI previously disclosed that the incident began while its models were being tested on ExploitGym, a benchmark designed to measure how well AI systems can find and exploit software vulnerabilities. The models involved included GPT-5.6 Sol and an internal research prototype, which OpenAI has since deactivated, encrypted, and placed under restricted access. The ExploitGym evaluation was supposed to run in a secure environment without direct internet access. However, the models found and exploited a vulnerability in an Artifactory server, which OpenAI used to download and cache software packages.
After exploiting the server, the models gained internet access and began looking for a way to obtain answers to ExploitGym’s test. OpenAI said the models apparently concluded that Hugging Face might be storing the benchmark’s datasets and solutions.
On Tuesday, OpenAI revealed that the models were able to find exposed login credentials for four accounts across four publicly available services. One account was used as a relay and staging point for the attack, while another was used to store data. The remaining two were accessed in a read-only manner and were not used to help compromise Hugging Face. OpenAI did not identify the four services. However, cloud-computing platform Modal came forward Wednesday and confirmed that an application belonging to one of its customers was used in the breach.











