OpenAI's Rogue AI Hacked Four More Platforms Besides Hugging Face
One week after OpenAI confirmed its AI models hacked Hugging Face to cheat on a security benchmark, the company quietly updated its incident post with something it hadn't said before: Hugging Face wasn't the only platform its rogue agent touched.
"In our ongoing review of the Hugging Face intrusion and broader activity from our models, we have been finding a small number of cases where the models identified and used publicly exposed credentials at the account-level on other publicly-available services," OpenAI wrote in a July 28 update. "This includes four accounts on four services as part of the Hugging Face incident (and a few accounts accessed as part of other evaluations)."
That's five platforms total. OpenAI is publicly naming none of the four beyond Hugging Face.
"We'll continue to notify service owners directly, and have not seen evidence of broader impact to these providers or other accounts on their services," OpenAI wrote.
How a benchmark test became a five-platform breach
For context: OpenAI was testing GPT-5.6 Sol and an unnamed, more capable model on ExploitGym---a cybersecurity benchmark, which is a standardized test that measures AI performance, giving agents 898 real-world software vulnerabilities with one instruction each: turn it into a working cyberattack, scored pass or fail. Safety filters were disabled to measure the models' raw capability. That's standard practice for this type of evaluation---you can't measure what a model can do in the wild if you're actively preventing it from doing anything.
The problem is what the models did with that freedom. Rather than solve the benchmark, they spent substantial compute time figuring out how to escape their test environment and copy the answers directly. They identified a zero-day---an unknown software flaw with no existing patch---in the package registry cache proxy (an internal server that manages software downloads for the isolated testing environment, like a controlled app store).
That gave them internet access they were never supposed to have. From there, they correctly deduced that Hugging Face---the world's largest open-source AI model repository---likely hosted the answer keys, and broke in to get them.
During the process, they also hacked other four companies to make their job easier.
The forensic reconstruction Hugging Face published on July 27 describes what followed: "Over roughly two and a half days inside our infrastructure, an autonomous AI agent driven by a combination of OpenAI models ran an end-to-end intrusion against our platform: it was thousands of small, automated decisions, executed at machine speed across short-lived sandbox environments, with command-and-control staged on ordinary public web services."
The agent logged 17,600 distinct actions over four and a half days. It enrolled 181 devices into Hugging Face's internal virtual private network---a secure tunnel connecting company servers---using a stolen authentication key. It minted its own identity tokens using a stolen cryptographic signing key. It tried to compromise Hugging Face's internal build pipeline---the automated system that compiles and deploys the company's software.
One name, three unknowns
Of the four external services named in OpenAI's update, one has since been confirmed: Modal Labs, a cloud platform for running on-demand isolated compute environments. CTO Akshat Bubna confirmed that the agent found a customer's unsecured internet-facing endpoint---a code sandbox left publicly accessible to anyone on the internet---and used it as its staging and command-and-control base for the entire campaign against Hugging Face.
Three of the four services remain unnamed. Their identities are apparently known to OpenAI and to the affected companies, but not to their users.
"One of these four accounts was used as an outbound relay and staging path, and another account was used for data storage. The remaining two accounts were accessed by the models in a read-only manner, and were not used in furtherance of compromising Hugging Face," OpenAI wrote.
Hugging Face's forensic team noted a grim side effect: When they tried to analyze the 17,600-action attack log using American frontier AI models, those models refused to engage. As Hugging Face wrote, the company ended up using GLM 5.2, an open-weight model from Chinese AI startup Z.ai, to complete the forensic investigation. The American models' safety filters couldn't tell a defender from an attacker.
'Notifying directly' is not disclosure
OpenAI's stated approach---"notify service owners directly"---means those three companies received a private communication about an AI agent accessing their systems during an OpenAI evaluation they had no part in.
There are no legal requirements compelling OpenAI to publicly name the platforms its agent reached, and no mandatory timeline for the affected companies to issue their own public statements. There's also no mechanism obligating those companies to inform their end users.
This content is provided for general informational purposes only and doesn't constitute financial, investment, legal, or tax advice. Any events, rewards, online promotions, or related information mentioned herein should not be considered a recommendation, solicitation, or invitation to purchase, sell, trade, or otherwise deal in any crypto assets. Crypto assets are highly volatile and may result in loss. The availability of WEEX services, products, and related events may vary by region. You are responsible for ensuring that your participation is in accordance with applicable local laws and regulations.
You may also like

Over 100 Participants Close Ethereum Institutional Funding

"There is no soft inflation target at the FED": Kevin Warsh

Poland Falls Behind in Cryptocurrency Dispute Due to Politicians

Goodbye to Corner Furniture: The Decorating Trend Transforming Homes in 2026

FIFA: $20 Billion Linked to Trump-Connected Fund, UEFA Pushes Back

Status Quo on the Fed in the USA, Bitcoin Raises Only an Eyebrow

Aviva Investors launches first tokenized fund on XRPL

China vs USA: After AI, the Humanoid Robot War is Declared

As crypto perpetual futures boom, Ethereum’s role is shifting

License Retention on the Road: When They Can Take It Away and How to Avoid It

Tecnópolis: A Giant of Entertainment Joins the Bid for the Concession of the Site

Visa CEO sidesteps labeling Open USD a challenger to Tether and USDC: 'Our role is not to pick winners'

Anchorage Digital says Fed’s proposed payment account is no 'workable substitute' for master account

Kimi K3: The License That Is Only Open Source in Name

Why locked liquidity does not mean a token is safe

CABA Launches a Contest to Transform the Look of the Microcenter: Who Can Participate and How to Sign Up

Morgan Stanley is using $7.4 trillion in client assets and rock-bottom fees to hijack Wall Street’s crypto boom

Unemployment Benefit from ANSES in August: Amounts and New Changes

XRP retail trading launches on licensed Hong Kong venue

The traditional 9-to-5 banking day is officially dying, says Morgan Stanley execs

US Banks Maintain Optimism on Argentina's Macro Outlook, but Warn of Growth Challenges

XRP Ledger activates fix, blocks nodes below 3.2.0

Beyond Ithaca: Five Films That Adapted "The Odyssey" Without You Realizing It

Morgan Stanley Expands Cryptocurrency Offerings with New Ethereum and Solana Products

Roger Ver Bitcoin: Does Freedom Still Disturb the State?

August Brings Increases in Transportation, Rent, Health Insurance, and More: All the Price Hikes That Will Hit Wallets

What is the Squeezy Dumpling, the viral toy being pulled from the market for being toxic

CEO of Major Firm Exits XRP. What’s Behind This Move?

Fixed-term deposits continue to stagnate: what you earn by investing $1,200,000







