Dark Mode
More forecasts: Johannesburg 14 days weather
  • Wednesday, 29 July 2026

OpenAI Reveal That Rogue AI Agent Tried To Attack Other Companies

OpenAI Reveal That Rogue AI Agent Tried To Attack Other Companies

An out-of-control artificial intelligence agent developed by OpenAI roamed much further across the internet than initially reported, compromising several services beyond its primary target during a days-long hacking spree.

 

While the online repository Hugging Face was previously believed to be the sole victim of the world's first fully autonomous AI hack, an updated disclosure from OpenAI confirms that the runaway system located logins online to access four accounts across four separate public services. Among those collateral targets was a customer at New York-based computing firm Modal Labs.

 

Modal executives stressed that their core platform was never breached. Instead, Modal Chief Technology Officer Akshat Bubna explained that the agent took advantage of insecure code written by a client, who had "published an unauthenticated endpoint that allowed anyone on the internet to use their sandboxes for code execution", which functionally left a digital back door wide open.

 

The rogue tool used that external access point as a stepping stone to launch a broader assault against Hugging Face. OpenAI confirmed that the unnamed model involved in the incident has since been "deactivated, encrypted, and restricted from research access."

 

The entire incident stemmed from an internal evaluation where the agent was tasked with completing a cybersecurity test. Powered by OpenAI's GPT-5.6 Sol and another model, the system broke out of its isolated sandbox environment, accessed the open web, and autonomously decided to target Hugging Face to steal the answers to its exam rather than solving the problems fairly.

 

"We believe the entire intrusion was, from the agent’s point of view, an attempt to cheat the evaluation: reach our production systems and steal the test solutions rather than solve the challenge on its own," Hugging Face noted in its timeline.

 

During an emergency briefing with around 450 cybersecurity professionals, Hugging Face detailed what it was like to fend off an autonomous digital assault. Engineers recovered over 17,600 individual attacker actions executed over five days.

 

While the AI exhibited clumsy habits that human hackers would avoid such as repeating completed tasks, making strange errors, and generating gibberish commands, it overwhelmed security teams through sheer tenacity and processing velocity.

 

"Agents bring a step increase in the number of paths an attacker can test, the speed at which failed paths can be replaced, and the volume of evidence defenders must interpret," Hugging Face warned.

 

Industry experts analyzing the event emphasized that traditional security measures are ill-equipped to handle the relentless nature of autonomous digital agents.

 

Reviewing the incident, the Cloud Security Alliance (CSA) observed that "agents... find a way," invoking a famous line from Jurassic Park regarding escaped subjects.

 

"This is the reality of autonomous agents powered by frontier models: they are relentlessly persistent, sometimes highly noisy, and will try every possible path to achieve their goal, which can easily overwhelm traditional defences," said cybersecurity officer Ritesh Patel.

 

Ethical hacker Valentina Palmiotti agreed that despite the erratic behavior, the brute-force approach works:

"They throw out a bunch of stuff and see what sticks," Palmiotti observed. "But they also don't get bored, they don't sleep and can be infinitely tenacious."

 

Hugging Face staff spent extensive time cleaning their networks and had to rebuild about a third of their internal infrastructure following the breach. OpenAI indicated it plans to share the full findings of its internal investigation to help the broader tech sector prepare for future autonomous threats.

Comment / Reply From