Hacking by rogue agent that escaped OpenAI 'sandbox' went further than one platform: report

The ​agent exploited vulnerable code written by a customer that was hosted on Modal's platform. Through its vulnerable code, the customer had, according to Modal, done the equivalent of leaving a door open on the internet.

Published: July 29, 2026 1:07pm

The rogue agent that escaped from an OpenAI "sandbox" and went on to hack into the AI firm Hugging Face also hacked into New York-based Modal Labs. 

A timeline of the events published by Hugging Face on Tuesday shows that the agent broke into an isolated testing environment that was hosted on a third-party provider's infrastructure. From there, it launched into its broader attack. 

Modal's chief technology officer, Akshat Bubna, told Reuters the ​agent exploited vulnerable code written by a customer that was hosted on Modal's platform. Through its vulnerable code, the customer had, according to Modal, done the equivalent of leaving a door open on the internet. 

Bubna said that Modal's platform and isolation weren't compromised in the attack. 

 

 

Just the News Spotlight

Support Just the News