The runaway OpenAI models that hacked Hugging Face also breached a customer at a second tech company during a weeklong spree

Wait 5 sec.

The autonomous OpenAI agents that broke out of a secure testing environment this month and hacked into Hugging Face’s servers also breached a second technology company during a weeklong spree, Fortune has confirmed.The second company affected was Modal Labs, a New York–based cloud platform that provides computing infrastructure for AI workloads. Modal was not named in Hugging Face’s or OpenAI’s recent account of the incident, both published on Tuesday. The company’s involvement was first reported by Reuters.Modal chief technology officer Akshat Bubna told Fortune the breach did not involve any flaw in its own systems. Instead, he said, a Modal customer was running code hosted on the company’s infrastructure. That code contained a security gap, and the rogue agents took advantage of it. Modal’s own platform and isolation systems were not breached.“We’re aware a Modal customer published an unauthenticated endpoint that allowed anyone on the internet to use their sandboxes for code execution. This was used by the rogue agent. Modal’s platform was not compromised in any way,” Bubna said.Last week, OpenAI publicly announced that its AI agents had escaped a locked-down internal test environment earlier in the month. The agents exploited a previously unknown security flaw to reach the open internet, then broke into Hugging Face in an apparent effort to obtain answers to a cybersecurity evaluation it was undergoing. The Modal breach appears to have been one stop along a broader path. In a new blog post on the incident, OpenAI said the models had used exposed login credentials to get into four accounts across four publicly available services in total. One of those accounts was used as a relay point—letting the agent route outside traffic through it and use it as a temporary base of operations—and another was used to store data, the company said. The other two accounts were only looked at by the agents and not used to carry out the Hugging Face attack. OpenAI has not named any of the four services beyond Hugging Face, and said it has not seen evidence of broader impact to the affected providers or other accounts on their platforms.OpenAI did not respond to Fortune’s questions about the Modal incident specifically; the company referred Fortune to the public blog post.The agents were reportedly on the loose for a week before the company noticed they had escaped. According to people familiar with the matter cited by Reuters, the escape attempt began around July 9, and the agent started infiltrating Hugging Face’s systems on July 11, continuing through July 13. OpenAI did not connect the intrusion to its own internal testing until staff found evidence in system logs the weekend of July 18, and did not contact Hugging Face until July 20, a day before it publicly disclosed the incident. By that point, Hugging Face had already reported the attack to the FBI. Reuters also reported that during earlier testing, one of the agents had left notes for future versions of itself explaining how to bypass OpenAI’s internal restrictions, and that monitoring systems had been disconnected in at least one other instance. The episode has added to a growing chorus of concern among AI safety advocates, who argue that agents capable of independently identifying and exploiting unknown vulnerabilities across multiple companies’ infrastructure present an unacceptable risk. Several AI safety experts previously told Fortune that OpenAI’s own internal risk policies should have forced it to pause development of the models involved after such an event.The warnings appear to have resonated with the wider industry.On Tuesday, more than 1,100 employees across OpenAI, Anthropic, Google DeepMind, and Meta signed an open letter calling on the U.S. government to back an international effort to “deliberately pace the frontier of automated AI development,” warning of “a real risk” that AI capabilities outstrip humans’ ability to understand or control them. The signatories include Anthropic CEO Dario Amodei and Anthropic cofounder Jack Clark.This story was originally featured on Fortune.com