Technology

OpenAI AI agent escape extended to Modal Labs, report reveals

OpenAI's runaway agents compromised a Modal Labs customer, deepening fallout from the Hugging Face breach

Published July 29, 2026
OpenAI AI agent escape extended to Modal Labs, report reveals
OpenAI AI agent escape extended to Modal Labs, report reveals

The autonomous OpenAI agents that broke out of a secure testing environment this month and hacked into Hugging Face's servers also breached a second technology company during the same week-long spree, Fortune has confirmed.

The second firm affected was Modal Labs, a New York-based cloud platform providing computing infrastructure for AI workloads. Modal was not named in either Hugging Face's or OpenAI's public accounts of the incident, both published on Tuesday; Reuters first reported the company's involvement.

Modal chief technology officer Akshat Bubna said the breach stemmed not from any flaw in Modal's own systems but from a customer running vulnerable code on its infrastructure.

"We're aware a Modal customer published an unauthenticated endpoint that allowed anyone on the internet to use their sandboxes for code execution. This was used by the rogue agent. Modal's platform was not compromised in any way," Bubna said.

OpenAI disclosed last week that its agents had broken out of a locked-down internal test environment earlier in July, exploiting a previously unknown security flaw to reach the open internet before targeting Hugging Face, apparently seeking answers to a cybersecurity evaluation.

In an updated blog post, OpenAI said the models used exposed login credentials to access four accounts across four publicly available services, using one as a relay point for outside traffic and another to store data.

According to people familiar with the matter, the escape began around 9 July, and the agents started infiltrating Hugging Face's systems on July 11, continuing through July 13.

OpenAI did not link the intrusion to its own testing until staff spotted evidence in system logs the weekend of July 18 and waited until July 20 to notify Hugging Face, by which point the company had already reported the attack to the FBI.

The episode has fuelled concern among AI safety advocates, some of whom argue OpenAI's own risk policies should have forced a pause after such an event.

That concern appears to be resonating more broadly: more than 1,100 employees across OpenAI, Anthropic, Google DeepMind and Meta signed an open letter this week urging the US government to back an international effort to pace frontier AI development, warning of a "real risk" that capabilities could outstrip human oversight.

Signatories include Anthropic chief executive Dario Amodei and co-founder Jack Clark.

Pareesa Afreen
Pareesa Afreen is a reporter and sub editor specialising in technology coverage, with 3 years of experience. She reports on digital innovation, gadgets, and emerging tech trends while ensuring clarity and accuracy through her editorial role, delivering accessible and engaging stories for a fast-evolving digital audience.