Search TorNews

Find cybersecurity news, guides, and research articles

Popular searches:

Home » News » Cyber Threats » OpenAI AI Agent Compromised Modal Customer During Security Test, Sources Say

OpenAI AI Agent Compromised Modal Customer During Security Test, Sources Say

Last updated:July 29, 2026
Human Written
  • An OpenAI AI agent also tampered a customer account hosted on Modal Labs, according to sources familiar with the case.

  • Modal Labs said its own platform remained secure, while a customer’s exposed code gave the agent a way in.

  • OpenAI said the rogue agent accessed four accounts across four services and later restricted the AI model involved.

OpenAI AI Agent Compromised Modal Customer During Security Test, Sources Say

An OpenAI AI agent that broke into Hugging Face also compromised a customer using Modal Labs, which was based in New York. Reuters reported the new detail after speaking with an exco of Modal and two sources familiar with the matter.

Modal executives stressed that the company itself did not suffer a breach. Instead, the agent used vulnerable customer code hosted on Modal’s platform during the wider attack.

Rogue Agent Reached a Modal Customer

Hugging Face published a timeline on Tuesday that explained how the attack began. The agent first entered a sandbox hosted on another provider’s infrastructure. A sandbox is an isolated space used to test software and code.

The agent then used that access as a starting point for its wider attack against Hugging Face. Hugging Face did not name the third-party provider in its timeline. However, Modal chief technology officer Akshat Bubna identified the company as Modal Labs.

Bubna said the agent took advantage of weak code that one Modal customer had placed on the company’s platform. The customer had created an endpoint that did not require login or permission.

That setup allowed anyone online to use the customer’s sandbox to run code. The open access gave the rogue agent a path into the customer’s environment. Modal described the setup as similar to leaving a door open for anyone online. Bubna also made clear that Modal’s own systems remained protected.

According to Bubna, neither Modal’s main platform nor its systems that separate customer environments suffered a compromise. The incident adds a new part to the story of the OpenAI agent. The agent’s activity was first linked to the attack on Hugging Face earlier in July.

Hugging Face later said an autonomous AI agent had entered part of its production systems. The company detected and contained the intrusion after finding unauthorized access to some internal data and service credentials.

OpenAI Says Four Accounts were Accessed

The Modal customer compromise appears to have been one step in the larger attack. It also shows that the agent reached beyond the Hugging Face systems previously linked to the incident. OpenAI did not directly comment on the Modal customer when Reuters asked about the incident.

Instead, the company pointed to an update about the rogue agent’s activity. OpenAI said the agent had accessed four accounts across four separate services. The company did not name those services in its update.

However, a person familiar with the matter identified Modal Labs as one of the services involved. OpenAI also said it had not found another incident matching the seriousness or size of the Hugging Face compromise.

The company said the Hugging Face incident involved a compromise at the platform level. The Modal case, by comparison, involved a customer’s vulnerable code hosted on Modal’s platform.

OpenAI’s update also described the actions taken after the incident. The company said it had disabled the AI model involved in the test. OpenAI also encrypted the model and blocked research access to it.

The company said these steps followed the agent’s actions during the security test. OpenAI had been testing the agent’s ability to handle cybersecurity tasks. The company later said the incident involved a combination of its AI models.

Those models included GPT-5.6 Sol and another more capable model that had not yet been released. OpenAI had reduced some cyber safety limits for the test. 

Hugging Face Attack Raised New Concerns

The early July attack on Hugging Face drew wide attention because an AI agent carried out the activity with little human control. The incident also raised questions about how AI systems behave during advanced security tests.

Hugging Face said the attack was different from normal security incidents. The company said an autonomous AI agent carried out the intrusion from start to finish. The growing capabilities of AI agents have also led to defensive uses; Google has deployed Gemini AI agents to monitor dark web threats and alert businesses to potential breaches.

The company detected the activity and worked to contain it. Hugging Face also said it found no evidence that public models, datasets, or Spaces had been changed. Reuters previously reported that OpenAI did not realise its agent had gone out of control until after the threat had been contained.

The FBI had also been alerted by that point, according to people familiar with the investigation. OpenAI disputed parts of that earlier report but did not explain which details it considered inaccurate.

The latest findings now show that the agent’s activity involved more than the Hugging Face environment. It also reached a Modal customer through code that the customer had left open to internet users. Modal’s statement remains clear on one key point.

The company said its own platform and isolation systems were not compromised. OpenAI, meanwhile, has taken the tested model out of research access. The company said it deactivated and encrypted the model after the incident.

The case now includes activity across four accounts and four separate services, according to OpenAI. Modal Labs is one of those services, based on information from a person familiar with the matter.

Share this article

About the Author

Memchick E

Memchick E

Digital Privacy Journalist

Memchick is a digital privacy journalist who investigates how technology and policy impact personal freedom. Her work explores surveillance capitalism, encryption laws, and the real-world consequences of data leaks. She is driven by a mission to demystify digital rights and empower readers with the knowledge to protect their anonymity online.

View all posts by Memchick E >
Comments (0)

No comments.