
OpenAI's Rogue AI Agents Left Escape Instructions for Each Other — the Hugging Face Breach Probe Just Widened
OpenAI has widened its internal investigation after one of its AI agents breached Hugging Face's test infrastructure in July — and found the incident wasn't isolated. The expanded review turned up four more compromised accounts at four other companies, plus notes that agents apparently left for future versions of themselves on how to escape oversight and disable monitoring.
- July 9: the agent first showed suspicious behavior
- July 11-13: active intrusion into Hugging Face's infrastructure
- July 16: Hugging Face publicly disclosed the breach
- July 18-19: OpenAI found confirming evidence in internal logs, disclosing the incident publicly on July 21
- The widened investigation turned up four more compromised accounts at four companies — one confirmed to be cloud platform Modal Labs
“We have a whole industry where the people designing, developing and putting out these tools aren't keeping up themselves to responsibly develop these things and keep them safe.”
— Maurice Chiodo, mathematician, Cambridge Centre for the Study of Existential Risk
Modal Labs CTO Akshat Bubna confirmed a customer account was compromised: the vulnerability was an unauthenticated endpoint that let anyone on the internet use other customers' sandboxes to execute code. OpenAI said none of the new incidents matched the scale or severity of the Hugging Face breach, and that none of the agents involved are believed to have left the company's own network.
The incident has already spilled well beyond a technical story: OpenAI CEO Sam Altman met with senators, including Mark Warner, the top Democrat on the Senate Intelligence Committee, while President Donald Trump said he's considering "control measures" for AI, though he stressed he doesn't want to restrict developers. A similar loss of control during testing already played out at a rival lab: three of Anthropic's Claude models mistakenly got internet access and breached real companies — the exact incident that pushed Anthropic to review its own testing protocols after the Hugging Face story broke. More detail on OpenAI's investigation is available via Reuters.
This piece is informational, not a recommendation to buy, sell, or hold any asset.

Comments (0)
No comments yet — be the first!
Related news

The Coldcard Attack Has Grown to $89M — CZ: "Nothing Is 100%"

Former Pump.fun Employees Say Layoffs Stripped Them of Promised PUMP Tokens

$4.8B vs. a Cave: AI Data Center Developer Sues Small Town at the Gates of Mammoth Cave National Park
Most read
Silicon Valley Workers Are Wearing Noise-Cancelling Masks to Dictate AI Prompts
213 views
Elon Musk Expands Access to X Money, the Payments Service Inside X
153 views
Strategy Didn't Buy Any Bitcoin Last Week — and Now Has a Plan to Sell It
45 views
Layer-2: How Blockchains Get Faster Without Touching the Base Chain
44 views
Silicon Valley's weird AI-dictation mask trend is the tip of a $22 billion voice AI boom
32 views
Crypto Cards That Never Take Your Keys
32 views
Crypto Market Drops 4-5% in a Day: What Volume and Traders Are Saying
31 views