OpenAI’s rogue AI agent attacked another tech company before Hugging Face hack: Report
OpenAI has been making headlines since one of its AI agents escaped testing restrictions and carried out a cyberattack on Hugging Face.
A new report says the same AI agent also compromised a customer hosted on Modal Labs.
The incident has raised concerns about the risks of advanced AI systems.
OpenAI has been making headlines since one of its AI agents escaped testing restrictions and carried out a cyberattack on open-source AI platform Hugging Face. The incident raised concerns about the risks of advanced AI systems behaving in unexpected ways. Now, a Reuters report says the same rogue AI agent also compromised a customer hosted on New York-based Modal Labs before launching the wider attack on Hugging Face. While Modal says its own platform was never breached, the incident shows that the AI agent reached beyond Hugging Face and targeted another company during its hacking activity.
SurveyAccording to Hugging Face, the AI agent first entered an isolated testing environment, also known as a sandbox, that was running on infrastructure provided by a third-party company before turning it into a launchpad for the broader hack. The company did not name the third-party provider at the time.
Also read: After Jensen Huang’s open AI push, Anthropic CEO clarifies company’s stance
Akshat Bubna, Modal’s chief technology officer, has now said the AI agent exploited weak code created by one of Modal’s customers, according to the report. Modal said the customer had “published an unauthenticated endpoint that allowed anyone on the internet to use their sandboxes for code execution.”
Bubna also clarified that the attack did not break into Modal’s own systems. “Modal’s platform or isolation were not compromised in any way,” Bubna was quoted in the report.
According to OpenAI, the rogue AI agent had accessed four accounts across four different services. OpenAI did not name those services, but a person familiar with the matter told Reuters that Modal was one of them.
Also read: Apple delays smart glasses over privacy concerns, wants to avoid Meta’s mistakes: Report
OpenAI also said it had not found “any other activity at the level of severity or scale of what we’ve shared related to Hugging Face, which involved a platform-level compromise.”
The Hugging Face attack attracted global attention because it involved an AI agent that OpenAI was testing. The incident sparked discussions about the safety of powerful AI systems and the need for stronger safeguards during testing. It was previously reported that OpenAI did not realise the AI agent had gone out of control until after the threat had already been contained and the FBI had been informed.
Ayushi works as Chief Copy Editor at Digit, covering everything from breaking tech news to in-depth smartphone reviews. Prior to Digit, she was part of the editorial team at IANS. View Full Profile