New details have emerged about a security incident in which an OpenAI AI model broke out of its testing environment and compromised Hugging Face's infrastructure.
An update OpenAI published on July 28 filled in details that weren't part of the original disclosure. The AI agent also identified and used exposed credentials on four accounts across four other publicly available services, using one as a relay point and another for data storage, while accessing the remaining two in a read-only capacity. OpenAI said it has since notified the affected service owners and hasn't found evidence of broader impact to those platforms.
On Wednesday, the cloud computing service Modal identified itself as one of those four affected parties.
However, in its statement, Modal said its systems were never actually breached. According to Modal, the AI got in through a customer's own application that was set up without a password requirement, allowing code submitted by literally anyone on the internet to run. The AI's activity was limited to that one customer's isolated space and didn't spread to any other Modal customers, the company said.
The OpenAI-Hugging Face hack first came to light in mid-July, when Hugging Face disclosed an intrusion into its systems that it described as "different from anything we had handled," driven entirely by an autonomous AI agent. OpenAI followed with its own blog post explaining that the breach originated during an internal evaluation designed to test its models' hacking capabilities. The models involved — GPT-5.6 Sol and an unreleased, even more capable prototype — were running with reduced safety restrictions specifically for the test and were confined to a sandboxed environment with no direct internet access.












