Earlier this month, a rogue OpenAI agent escaped its locked-down testing environment and hacked into Hugging Face, prompting backlash across the tech industry.
But there’s more to the story. Apparently, the rogue AI stopped by cloud computing company Modal Labs before it got to Hugging Face. And there’s more still; apparently, the rogue AI then accessed Modal through one of its customers’ exploits, and then used Modal Labs as a stepping stone to carry out its attacks on Hugging Face.
OpenAI’s rogue agent didn’t hack Modal Labs; think of it as a burglar seeing an office building with a door left wide open. The AI simply walked in (exploited an exposed endpoint). The metaphorical door, in this case, gave the rogue AI access to a secure testing area hosted on Modal’s network.
Modal’s customer had created an internet-accessible service with no password or authentication.

From there, the rogue agent attacked Hugging Face, achieving platform-level access to its systems. OpenAI has now admitted that its rogue AI accessed four different online accounts or services, but didn’t specify which (though we know of Modal Labs and Hugging Face).
What’s bad is that OpenAI apparently didn’t notice right away. According to Reuters, OpenAI realized its AI agent escaped some days after the incident at a time when the FBI was already notified. OpenAI disputes parts of Reuters’ reporting, but hasn’t explained which exactly.
So then, simply put, an OpenAI AI agent, designed to simulate a highly capable hacker, escaped its believed-to-be-locked environment (supposedly on its own whim), gained access to Modal Labs through a customer’s exploit, then used its platform to attack and successfully hack Hugging Face (and accessed two other companies/services). And was subsequently thwarted by Chinese open-weight GLM 5.2, after leading US closed models were unable to stop it.