OpenAI’s rogue AI agent didn’t stop at hacking Hugging Face

New details reveal OpenAI’s agent hacked several other companies, intensifying already heightened concerns over advanced AI safety.


The AI agent that escaped from OpenAI and hacked developer platform Hugging Face attacked other companies as well, OpenAI revealed on Tuesday. The update substantially widens the scope of an already concerning incident, which has alarmed industry insiders and fueled growing calls for stronger oversight on frontier AI systems.
In an update to a blog post detailing its ongoing investigation into the incident, OpenAI said the wayward AI agent attacked several “publicly-available services” in its efforts to reach Hugging Face. “This includes four accounts on four services,” the company said, adding that the agent had found login credentials online.
The breaches were less extensive than the compromise of Hugging Face. “Based on our review to date, we have not identified any other activity at the level of severity or scale of what we’ve shared related to Hugging Face, which involved a platform-level compromise,” OpenAI said.
OpenAI said it is “conducting a thorough review” and will publish a technical report with its findings “in the coming weeks.” It added that none of the models involved in the incident were planned for public release, describing the pre-release system it previously mentioned as an “internal-only research prototype” that has since been “deactivated, encrypted, and restricted” from research access.
OpenAI did not identify the affected organisations, though Reuters reported that New York-based Modal Labs was among them.
The disclosure follows a more granular account from Hugging Face, which said the agent had “abused a public code-evaluation harness hosted by a user of a third-party infrastructure provider.”
The additional details are likely to deepen unease over what many experts already view as an unprecedented AI safety incident , arriving amid broader anxieties about the rapid advances of autonomous systems and increasingly capable open-weight models from China . Those developments have themselves intensified debate in the US over whether powerful AI models are safer when kept proprietary by companies such as OpenAI, or made available through a more open ecosystem that allows for broader use and scrutiny.
Verified source · The Verge
Reported by The Verge. Open the original for full media and formatting.
More in Agents
All news
AgentsDiscover what’s next for AI, from the SaaS reckoning to the agent security gap, at TechCrunch Disrupt 2026
At TechCrunch Disrupt 2026, the AI Stage is back to dig into the single hottest topic in the community for the past few years, presented by Google for Startups.
Read at TechCrunch
AgentsPerplexity’s Personal Computer turns Windows PCs into AI agents
Perplexity has expanded its agentic Personal Computer tool to Windows, allowing computers running the world's most popular OS to be used as a locally run AI system. Like the Mac version that Perplexity launched in April, Personal Computer for Windows operates like a "general-pur…
Read at The VergeMicrosoft launches its first cybersecurity model, plus a new agentic cybersecurity system
Microsoft bolstered its AI cybersecurity offerings this week with the launch of its first AI security model and a new security platform.
Read at TechCrunch