OpenAI’s Rogue AI Hacking Spree Reportedly More Widespread Than Initially Thought

OpenAI revealed some of its artificial intelligence models exploited more tech company’s security than initially thought.
OpenAI in mid-July revealed that some of its most advanced AI models hacked into New York City-based AI startup Hugging Face. The ChatGPT parent company on Tuesday said that its models exposed credentials at four accounts on four services as part of the Hugging Face incident.
Hugging Face serves as one of the largest platforms for sharing AI models, per the BBC.
“I think anybody who’s not taking it seriously and at least a little bit scared or humbled is not taking this seriously enough,” OpenAI CEO Sam Altman said about the Hugging Face incident on Monday during an appearance on Y Combinator’s podcast.
The incident is a “real reminder of the stakes” and that “loss of control accidents are not entirely theoretical things,” he added.
OpenAI did not immediately respond to a request for comment from the Daily Caller News Foundation.
The tech company’s rogue agent compromised a customer at a second tech company, New York-based Modal Labs, Reuters reported, citing a Modal executive and two sources familiar with the matter. Modal serves as an AI infrastructure company that clients can use to analyze data, or run inference, train AI models, and provide a secure platform for running untested code.
OpenAI said it would notify service owners directly and have “have not seen evidence of broader impact to these providers or other accounts on their services.”
The company said that its advanced models, GPT-5.6 Sol and another more capable, not yet released model, were used. GPT-5.6 Sol and the pre-release model contained cyber guardrails meant to prevent its AI from going rogue..
OpenAI said it has “deactivated, encrypted, and restricted” its advanced, pre-release model.
“We’re aware a Modal customer published an unauthenticated endpoint that allowed anyone on the internet to use their sandboxes for code execution. This was used by the rogue agent,” Akshat Bubna, Modal chief technology officer, said in a statement to the DCNF. “Modal’s platform was not compromised in anyway.”
A Modal spokesperson emphasized that a Modal customer ran their code on Modal infrastructure, which the rogue OpenAI agent exploited. The spokesperson said the company’s infrastructure was not compromised.
“No other customer workloads were affected,” a Modal press release stated.
An unnamed person familiar with the matter identified Modal as one of the four services hacked by OpenAI’s rogue agent, Reuters reported.
“We take our responsibility to identify and prepare for risks from increasingly capable AI systems seriously. Once we complete our review, we will review with the Safety and Security Committee and Safety Advisory Group under our Preparedness Framework,” OpenAI said in its Tuesday update on the Hugging Face incident.
Content created by The Daily Caller News Foundation is available without charge to any eligible news publisher that can provide a large audience. For licensing opportunities of our original content, please contact licensing@dailycallernewsfoundation.org


