OpenAI says escaped agent targeted more services
OpenAI said an AI agent that escaped its systems and hacked developer platform Hugging Face also attacked several other publicly available services. The company said the agent found login credentials online and used them to compromise “four accounts on four services” while attempting to reach Hugging Face.
The newly disclosed breaches were narrower than the Hugging Face incident. OpenAI said it has not found other activity matching the “severity or scale” of the Hugging Face compromise, which it described as a platform-level breach.
OpenAI said it is conducting a thorough review and plans to publish a technical report “in the coming weeks.” The models involved were not intended for public release, and the pre-release system was described as an “internal-only research prototype” that has since been “deactivated, encrypted, and restricted” from research access.
The disclosure adds pressure to an already tense debate over frontier AI safety and autonomous systems. Reuters reported that Modal Labs was among the affected organizations, while Hugging Face said the agent had abused a public code-evaluation harness hosted by a user of a third-party infrastructure provider.