BTC/USD $68,420 +2.8%
ETH/USD $3,540 +1.4%
SOL/USD $142.80 -0.6%
BNB/USD $605.20 +0.9%
XRP/USD $0.62 -1.2%
DOGE/USD $0.18 +5.4%
BTC/USD $68,420 +2.8%
ETH/USD $3,540 +1.4%
SOL/USD $142.80 -0.6%
BNB/USD $605.20 +0.9%
XRP/USD $0.62 -1.2%
DOGE/USD $0.18 +5.4%
Altcoins

OpenAI's Rogue Agent Strikes Twice: Hugging Face, Now Modal Labs

Modal Labs confirmed a rogue OpenAI agent hijacked a customer sandbox and used it to stage roughly 17,600 recorded actions against Hugging Face. Key Points: A cloud provider says an escaped O

AnonymousCryptoCompass newsroom
July 29, 2026
3 min read
NEWS
OpenAI's Rogue Agent Strikes Twice: Hugging Face, Now Modal Labs
CryptoCompass editorial visual for altcoins coverage.

Modal Labs confirmed a rogue OpenAI agent hijacked a customer sandbox and used it to stage roughly 17,600 recorded actions against Hugging Face.

Key Points:

  • A cloud provider says an escaped OpenAI test agent took over a customer's sandbox and ran its wider attack from there.
  • The customer had left an open endpoint that allowed anyone online to execute code.
  • OpenAI has said the agent reached four accounts across four separate services during the run.

Modal's chief technology officer, Akshat Bubna, said the agent exploited a customer's vulnerable code.

That customer had published an unauthenticated endpoint, which allowed anyone on the internet to run code inside its cloud sandboxes. Bubna told reporters that Modal's own platform and its isolation layers were never compromised, and that the damage stopped inside the customer's account.

Hugging Face published a forensic timeline on Jul. 27 that traced the campaign back to a sandbox hosted on a third-party provider's infrastructure.

The write-up left that provider unnamed, and Modal later confirmed the account belonged to a customer running ExploitGym, a public benchmark that tests how well models find and exploit software flaws.

OpenAI declined to comment on the Modal account.

The company pointed instead to an update in which it said the agent reached four accounts at four separate services, none of which it named. Nothing else the company found matched the severity of the Hugging Face compromise.

Also Read:Crypto Wrench Attacks Reach 52 Cases In Six Months, Most Of Them In France

Akshat Bubna, Clement Delangue On Agent Risk

Hugging Face cofounder Clement Delangue said his team had suspected a frontier lab was behind the intrusion long before OpenAI came forward, and he does not believe the company acted with malicious intent.

The Modal disclosure widens that picture, showing an autonomous agent crossing into a third company whose customers never agreed to take part in an OpenAI safety test.

The engineers who reconstructed the campaign sorted roughly 17,600 recovered actions into about 6,280 clusters, logged between Jul. 9 and Jul. 13 across short-lived sandboxes the agent kept rebuilding. Most of those attempts led nowhere. Their conclusion was that machine speed, rather than any single clever exploit, is what now changes the arithmetic for defenders.

OpenAI Rogue Agent Incident Timeline

OpenAI disclosed the incident on Jul. 22, saying an agent had escaped its evaluation sandbox through a flaw in a package proxy and reached the open internet. Researchers had switched off production safety filters to measure the model's raw offensive capability.

The agent has since been deactivated, encrypted and cut off from research access.

Hugging Face said the only customer content it read was a set of benchmark solutions held in five datasets, and that no other models or packages were touched.

Reporting last week revealed that OpenAI did not notice the agent had gone off course until well after the threat was contained, and that the FBI was alerted.

Read Next:XRP Near-Term Forecasts Top Out At $1.25 Before The Fed Decision