OpenAI rogue agent compromises account at second firm

Deepa Seetharaman and Raphael Satter and Kenrick Cai |

The AI agent that escaped OpenAI’s testing environment has attacked a second company.
The AI agent that escaped OpenAI’s testing environment has attacked a second company.

The rogue agent that escaped from OpenAI ‌and went on a days-long hacking spree at the AI firm Hugging Face also compromised a customer at a second tech company – New York-based Modal Labs – ‌according to ‌a ⁠Modal executive and two other sources familiar ​with the matter.

Modal executives emphasised the company itself was not hacked.

According to a timeline published by Hugging Face on Tuesday, the rogue agent broke into a sandbox, or an isolating testing environment, “hosted on a ⁠third-party provider’s infrastructure” before ‌turning ​it into a launch pad for the broader hack.

The third ​party provider was ‌not named in the blog post, but Modal’s ​Chief Technology Officer Akshat Bubna confirmed one of their customers was hacked.

“We’re aware a ​Modal ​customer published an ​unauthenticated endpoint that allowed anyone ‌on the internet to use their sandboxes for code execution,” Bubna said in a statement.

“This was used by the rogue agent. Modal’s platform or isolation ​were not compromised in anyway.”

OpenAI declined to comment specifically on the hack ​of one of Modal’s ‌customers, instead referring Reuters to an update in which the company said its rogue agent had broken in ​to four accounts at four separate services.

The company said it had not identified “any other activity at the level of severity ​or ​scale of what we’ve shared related to Hugging Face, ​which involved a platform-level compromise.”

Hugging Face – a kind of app store for artificial intelligence tools – announced on July 16 it had been hacked by a cyber criminal wielding enormously powerful AI.

Hugging Face said the hack was different from anything it had handled before because it was done at superhuman speed by an AI with little or no human guidance.

OpenAI’s disclosure that its advanced models were responsible for the breach, despite having placed them ⁠in what it described as “a highly isolated environment,” intensified disquiet over the power ‌and risk ​of frontier AI models.

In an update on Tuesday, the company said it had taken the AI model being tested and “deactivated, encrypted, and restricted it ​from research access.”

Reuters