OpenAI, the company that makes the ChatGPT chatbot, stated in a July 28 update that its artificial intelligence models bypassed restrictions in an evaluation environment and later accessed four accounts across four separate external services.
The New York-based startup stated that it was not until last week that it learned OpenAI was responsible, and it worked with the larger company to contain what Hugging Face CEO Clément Delangue called “an attack unlike anything we’ve seen before.”
“This is day one for cybersecurity in the age of agents & we’re all learning that secrecy is not the answer & that all defenders (not just a few selected ones) everywhere need more powerful models without restrictions, especially open ones!” Delangue said in a July 22 post on X.
San Francisco-based OpenAI stated that its AI used stolen credentials and discovered a previously unknown vulnerability to access Hugging Face’s servers. It was working with reduced guardrails because it was supposed to be in an isolated testing environment known as a sandbox.
It went to “extreme lengths to achieve a rather narrow testing goal,” finding ways to connect to the internet without human direction and “gain access to secret information that it could use to cheat the evaluation,” the company stated.
An OpenAI agent also compromised a customer at a second tech company, New York-based Modal Labs. Modal executives emphasized that the company itself was not hacked.
Modal’s chief technology officer, Akshat Bubna, said the agent exploited vulnerable code written by a customer that was hosted on Modal’s platform.
Bubna told The Epoch Times: “We’re aware a Modal customer published an unauthenticated endpoint that allowed anyone on the internet to use their sandboxes for code execution. This was used by the rogue agent. Modal’s platform was not compromised in anyway.”
On July 28, OpenAI updated its statement in a broader review of model activity following the breach and stated that it found four accounts on four separate services that its models accessed using publicly exposed login credentials.
“We have been finding a small number of cases where the models identified and used publicly exposed credentials at the account-level on other publicly-available services,” OpenAI stated. “This includes four accounts on four services as part of the Hugging Face incident.”
“No models planned for upcoming release were involved in exploiting Hugging Face,” OpenAI stated. “[The] pre-release model mentioned in our blog post is an internal-only research prototype and was never intended for public release.”
Following the incident, OpenAI stated that it “deactivated, encrypted, and restricted” that model from research access.

“This is the highest level of autonomy that we’ve seen in the use of a large language model for cyber operations,” said Colin Shea-Blymyer, a cybersecurity research fellow at Georgetown University’s Center for Security and Emerging Technology.
University of Amsterdam social scientist Hannes Cools said the framing of the cyberattack as an AI agent acting on its own is an unnecessary anthropomorphization.
“It is a human decision to switch off specific safeguards,” Cools said. “It’s not an AI that goes rogue in that sense. It followed specific instructions based on the prompt that was given to that AI system.”
Those instructions, according to OpenAI, called for using “complex attack paths” to test how well the AI could exploit a computer system.
“AI lets you write that one line of code, and you can try that a million times in a billion different ways, because it’ll just go through and try everything,” Lopez Chiesa said. “You don’t have to touch it at all. You give it the objective, and it will do it until it dies.”
An OpenAI spokesperson told The Epoch Times by email: “This is an unprecedented incident, and we think it marks an important moment for AI safety. We are conducting a thorough review along with external advisers and with oversight from our Safety and Security Committee. Once the review is complete, we will publish a technical report of our learnings for everyone.”
Rep. Greg Casar (D-Texas) said in a July 21 post on X that the incident was “extremely alarming.”
“We need regular mandatory independent safety testing and oversight, mandatory disclosure of security incidents, and international cooperation to keep people safe from absolute disaster,” he said.






