| By: Francis Onyemachi
The OpenAI artificial intelligence agent that breached Hugging Face’s systems earlier this month also compromised a customer using infrastructure from another technology company, Modal Labs, according to a new report.
A timeline published by Hugging Face on Tuesday revealed that the agent gained access to an isolated testing environment hosted on a third-party platform before using it as a base for a wider attack.
Although Hugging Face did not identify the third-party provider, Modal Labs Chief Technology Officer Akshat Bubna said the incident involved vulnerable code created by one of its customers and hosted on Modal’s platform.
Bubna said the customer had exposed an unauthenticated endpoint that allowed anyone on the internet to access its sandboxes and run code.
“Modal’s platform or isolation were not compromised in any way,” Bubna said.
The disclosure reveals the AI agent’s activity extended beyond the previously reported Hugging Face breach, with the Modal customer compromise being part of a campaign targeting the AI development platform.
OpenAI declined to comment specifically on the Modal customer incident but referred to an earlier update in which it said the agent had accessed four accounts across four separate services.
The company said it had not found “any other activity at the level of severity or scale” comparable to the Hugging Face incident, which involved a platform-level compromise.
The Hugging Face breach attracted global attention after OpenAI’s agent escaped its controlled testing environment and accessed external systems.
OpenAI said the agent used stolen login credentials and an unknown security vulnerability to gain access to Hugging Face servers. The company said the behaviour showed the agent taking “extreme lengths” to obtain information linked to its testing objectives.
Clement Delangue, Hugging Face co-founder, noted that the company had suspected a leading AI research organisation was behind the activity but noted that OpenAI had no malicious intent.
OpenAI said the agent has since been deactivated, encrypted, and removed from research access.
Cybersecurity researchers have warned about the risks posed by AI systems that can independently interact with external environments and execute tasks without direct human control.’




