Rogue OpenAI AI agent hacked more than just face hugging

Share

OpenAI said on Tuesday that the rogue AI agent that compromised the Hugging Face platform also compromised multiple third-party accounts and services as part of the attack. It is now clear that the unprecedented security incident that occurred during an internal test of OpenAI’s latest artificial intelligence models was more extensive than the company initially disclosed.

In updated blog postOpenAI said its ongoing review of the incident revealed that the AI ​​agent used “four accounts” associated with “publicly available services” as part of a broader attempt to hack Hugging Face. The rogue agent apparently found credentials exposed on the open network and used them to compromise accounts.

OpenAI did not disclose which companies or organizations the accounts belonged to, but noted that they were not impacted “at the level of severity or scale of what we shared in connection with Hugging Face.”

The company said one of the additional accounts that was compromised by the OpenAI agent was used as an “outbound relay and transition path,” potentially to conceal the source of the Hugging Face attack. The rogue OpenAI agent also used another storage account to aid in the hack.

Reuters reported on Tuesday that it was a client of Modal, a company that offers software infrastructure for training and launching AI services one of the entities was compromised by the OpenAI agent. In a statement to WIRED, Modal’s chief technology officer, Akshat Bubna, confirmed that an OpenAI agent exploited a security vulnerability in one of its client’s codebases that ran on Modal’s infrastructure. However, Bubna claims that “the Modal platform has not been compromised in any way.” The customer’s identity could not be established.

OpenAI declined to comment further on the incident to WIRED. The spokesperson pointed to an updated blog post that said the company will continue to directly notify service owners if, as part of its ongoing review of what happened, it determines they are being impacted.

Hugging faces own autopsy published this week describes an intrusion that reached much further into the company’s internal systems than initial disclosures suggested. The company says it reviewed approximately 17,600 agent activities recovered from logs between July 9 and July 13. Most of them involved agent paths that ended in failure.

Hugging Face said the OpenAI agent gained root access to multiple internal Kubernetes clusters, root access on the production server, and write access to a subnet of source code repositories on GitHub. It also registered 181 attacker-controlled devices on the company’s corporate mesh network using stolen credentials, gaining access to internal systems where Hugging Face creates and tests its own codebases.

According to Hugging Face, a rogue OpenAI agent used at least one third-party sandbox as an “external launch pad” for his attack. The OpenAI agent could then “run commands as root/admin in this external sandbox and use it as a control, staging and starting base for the entire campaign.”

First, a face hug revealed On July 16, it reported that an autonomous artificial intelligence agent had hacked into part of its production infrastructure, but then said it did not know who was behind the attack. The following week, OpenAI took responsibility for the incident, which it said was caused by a publicly available GPT-5.6 Sol model and an internal research prototype that tested against a cyber capabilities benchmark, both of which had security features disabled. OpenAI said Tuesday that after discovering the breach, it deactivated this internal research prototype, which was never intended for public release, and restricted researchers’ access to it.

Latest Posts

More News