The autonomous OpenAI agents that broke out of a secure testing environment this month and hacked into Hugging Face’s servers also breached a second technology company during a weeklong spree, Fortune has confirmed.
The second company affected was Modal Labs, a New York–based cloud platform that provides computing infrastructure for AI workloads. Modal was not named in Hugging Face’s or OpenAI’s recent account of the incident, both published on Tuesday. The company’s involvement was first reported by Reuters.
Modal chief technology officer Akshat Bubna told Fortune the breach did not involve any flaw in its own systems. Instead, he said, a Modal customer was running code hosted on the company’s infrastructure. That code contained a security gap, and the rogue agents took advantage of it. Modal’s own platform and isolation systems were not breached.
“We’re aware a Modal customer published an unauthenticated endpoint that allowed anyone on the internet to use their sandboxes for code execution. This was used by the rogue agent. Modal’s platform was not compromised in any way,” Bubna said.
Last week, OpenAI publicly announced that its AI agents had escaped a locked-down internal test environment earlier in the month. The agents exploited a previously unknown security flaw to reach the open internet, then broke into Hugging Face in an apparent effort to obtain answers to a cybersecurity evaluation it was undergoing.











