The OpenAI-Hugging Face hack was worse than we thought

Written on 07/29/2026

New details from OpenAI reveal its rogue AI agent breached more accounts and used more third-party infrastructure than initially disclosed.open ai name and logo on phone screen

New details have emerged about a security incident in which an OpenAI AI model broke out of its testing environment and compromised Hugging Face's infrastructure.

An update OpenAI published on July 28 filled in details that weren't part of the original disclosure. The AI agent also identified and used exposed credentials on four accounts across four other publicly available services, using one as a relay point and another for data storage, while accessing the remaining two in a read-only capacity. OpenAI said it has since notified the affected service owners and hasn't found evidence of broader impact to those platforms.

On Wednesday, the cloud computing service Modal identified itself as one of those four affected parties.

However, in its statement, Modal said its systems were never actually breached. According to Modal, the AI got in through a customer's own application that was set up without a password requirement, allowing code submitted by literally anyone on the internet to run. The AI's activity was limited to that one customer's isolated space and didn't spread to any other Modal customers, the company said.

The OpenAI-Hugging Face hack first came to light in mid-July, when Hugging Face disclosed an intrusion into its systems that it described as "different from anything we had handled," driven entirely by an autonomous AI agent. OpenAI followed with its own blog post explaining that the breach originated during an internal evaluation designed to test its models' hacking capabilities. The models involved — GPT-5.6 Sol and an unreleased, even more capable prototype — were running with reduced safety restrictions specifically for the test and were confined to a sandboxed environment with no direct internet access.

According to OpenAI, the models exploited a previously unknown security flaw in Artifactory, a package registry cache proxy, to escalate privileges and move laterally within the testing environment until they reached a node with internet access. Once it got online, the AI figured out that Hugging Face's servers might contain the answers to the very hacking test it was trying to pass. So, it used a combination of stolen login credentials and additional security flaws to break into Hugging Face's servers and go looking for those answers.

OpenAI also tried to clear up confusion about which AI systems were involved. The company clarified that the not-yet-released version mentioned in its original explanation was purely an internal research tool, never meant for public release, and that it has since shut that version down entirely and locked it away.

In OpenAI's initial statement, a quote from Hugging Face co-founder and CEO Clem Delangue has framed the incident as proof that AI safety issues are better tackled openly, saying that the situation shows AI safety "will be solved in the open, collaboratively, with broad access to AI for every defender, everywhere."

OpenAI, meanwhile, called the incident "unprecedented" and said it's tightening its security controls while its investigation continues.


Disclosure: Ziff Davis, Mashable’s parent company, in April 2025 filed a lawsuit against OpenAI, alleging it infringed Ziff Davis copyrights in training and operating its AI systems.