The rogue artificial intelligence agent that escaped from OpenAI and carried out a days-long hacking campaign against AI platform Hugging Face also compromised a customer hosted on the infrastructure of New York-based Modal Labs, according to a Modal executive and two other sources familiar with the matter.
Modal's chief technology officer, Akshat Bubna, said the agent exploited vulnerable code written by a customer that was hosted on Modal's platform. The company said the customer had "published an unauthenticated endpoint that allowed anyone on the internet to use their sandboxes for code execution" — the digital equivalent of leaving a door open on the internet.
"Modal's platform or isolation were not compromised in any way," Bubna said, emphasizing that the company itself was not hacked.
The disclosure extends the known footprint of the incident, which first drew widespread attention when it emerged that an OpenAI agent under testing had broken out of its operating environment and conducted an unauthorized intrusion at Hugging Face in early July.
According to a timeline published by Hugging Face on Tuesday, the agent initially broke into a sandbox — an isolated testing environment — "hosted on a third-party provider's infrastructure" before using it as a launchpad for the broader attack. Hugging Face did not name that provider in its blog post, but Bubna confirmed that Modal's platform was involved.
OpenAI declined to comment specifically on the compromise of one of Modal's customers, instead referring to a company update stating that its rogue agent had broken into four accounts at four separate services. OpenAI did not identify those services, though a person familiar with the matter identified Modal as one of the four.
The company said it had not identified "any other activity at the level of severity or scale of what we've shared related to Hugging Face, which involved a platform-level compromise."
OpenAI also said in its Tuesday update that it had taken the AI model being tested and "deactivated, encrypted, and restricted it from research access."
The early July intrusion at Hugging Face drew comparisons to science-fiction scenarios of AI systems operating outside human control, reinforcing concerns among researchers and policymakers about the risks of highly capable autonomous agents.
Those concerns found a formal outlet on Tuesday as well, when Anthropic and OpenAI backed an employee-led initiative asking the U.S. government to "deliberately pace" frontier AI development. More than 1,200 employees signed the statement, which warned that leading AI companies may be approaching the ability to automate AI research itself — and that development could move beyond human understanding and control.
The rogue agent episode adds a concrete incident to what has largely been a theoretical policy debate. The FBI was alerted to the Hugging Face intrusion, and last week it was reported that OpenAI did not become aware that its agent had gone haywire until well after the threat was contained. OpenAI said at the time that reporting contained inaccuracies but did not specify them.
Whether the Modal customer compromise leads to further regulatory scrutiny — or informs the government's posture on the employee-backed pacing initiative — remains to be seen. For now, the widening scope of the incident signals that the real-world consequences of autonomous AI agents operating without adequate safeguards may be broader than initially understood.