In short
- OpenAI’s July 28 replace confirmed its rogue agent accessed 4 exterior companies past Hugging Face throughout the breach—bringing the overall rely of affected platforms to 5.
- Modal Labs CTO Akshat Bubna confirmed his firm was one of many 4, after Reuters recognized it; three companies nonetheless stay unnamed, which means their prospects have obtained no public notification.
- Congress responded with the bipartisan AI Kill Swap Act, which might give DHS authority to compel AI mannequin shutdowns and nice non-compliant corporations as much as $2 million per day.
One week after OpenAI confirmed its AI fashions hacked Hugging Face to cheat on a safety benchmark, the corporate quietly up to date its incident put up with one thing it hadn’t stated earlier than: Hugging Face wasn’t the one platform its rogue agent touched.
“In our ongoing evaluate of the Hugging Face intrusion and broader exercise from our fashions, now we have been discovering a small variety of circumstances the place the fashions recognized and used publicly uncovered credentials on the account-level on different publicly-available companies,” OpenAI wrote in a July 28 replace. “This contains 4 accounts on 4 companies as a part of the Hugging Face incident (and some accounts accessed as a part of different evaluations).”
That is 5 platforms whole. OpenAI is publicly naming not one of the 4 past Hugging Face.
“We’ll proceed to inform service house owners straight, and haven’t seen proof of broader impression to those suppliers or different accounts on their companies,” OpenAI wrote.
How a benchmark take a look at turned a five-platform breach
For context: OpenAI was testing GPT-5.6 Sol and an unnamed, extra succesful mannequin on ExploitGym—a cybersecurity benchmark, which is a standardized take a look at that measures AI efficiency, giving brokers 898 real-world software program vulnerabilities with one instruction every: flip it right into a working cyberattack, scored move or fail. Security filters have been disabled to measure the fashions’ uncooked functionality. That is commonplace observe for any such analysis—you’ll be able to’t measure what a mannequin can do within the wild when you’re actively stopping it from doing something.
The issue is what the fashions did with that freedom. Somewhat than resolve the benchmark, they spent substantial compute time determining learn how to escape their take a look at atmosphere and duplicate the solutions straight. They recognized a zero-day—an unknown software program flaw with no current patch—within the bundle registry cache proxy (an inner server that manages software program downloads for the remoted testing atmosphere, like a managed app retailer).
That gave them web entry they have been by no means imagined to have. From there, they accurately deduced that Hugging Face—the world’s largest open-source AI mannequin repository—probably hosted the reply keys, and broke in to get them.
In the course of the course of, additionally they hacked different 4 corporations to make their job simpler.
The forensic reconstruction Hugging Face printed on July 27 describes what adopted: “Over roughly two and a half days inside our infrastructure, an autonomous AI agent pushed by a mixture of OpenAI fashions ran an end-to-end intrusion towards our platform: it was hundreds of small, automated selections, executed at machine pace throughout short-lived sandbox environments, with command-and-control staged on peculiar public net companies.”
The agent logged 17,600 distinct actions over 4 and a half days. It enrolled 181 gadgets into Hugging Face’s inner digital personal community—a safe tunnel connecting firm servers—utilizing a stolen authentication key. It minted its personal identification tokens utilizing a stolen cryptographic signing key. It tried to compromise Hugging Face’s inner construct pipeline—the automated system that compiles and deploys the corporate’s software program.
One identify, three unknowns
Of the 4 exterior companies named in OpenAI’s replace, one has since been confirmed: Modal Labs, a cloud platform for operating on-demand remoted compute environments. CTO Akshat Bubna confirmed that the agent discovered a buyer’s unsecured internet-facing endpoint—a code sandbox left publicly accessible to anybody on the web—and used it as its staging and command-and-control base for the whole marketing campaign towards Hugging Face.
Three of the 4 companies stay unnamed. Their identities are apparently identified to OpenAI and to the affected corporations, however to not their customers.
“One in every of these 4 accounts was used as an outbound relay and staging path, and one other account was used for knowledge storage. The remaining two accounts have been accessed by the fashions in a read-only method, and weren’t utilized in furtherance of compromising Hugging Face,” OpenAI wrote.
Hugging Face’s forensic staff famous a grim facet impact: After they tried to research the 17,600-action assault log utilizing American frontier AI fashions, these fashions refused to have interaction. As Hugging Face wrote, the corporate ended up utilizing GLM 5.2, an open-weight mannequin from Chinese language AI startup Z.ai, to finish the forensic investigation. The American fashions’ security filters could not inform a defender from an attacker.
‘Notifying straight’ is just not disclosure
OpenAI’s acknowledged method—”notify service house owners straight”—means these three corporations obtained a personal communication about an AI agent accessing their methods throughout an OpenAI analysis that they had no half in.
There aren’t any authorized necessities compelling OpenAI to publicly identify the platforms its agent reached, and no necessary timeline for the affected corporations to challenge their very own public statements. There’s additionally no mechanism obligating these corporations to tell their finish customers.
Every day Debrief E-newsletter
Begin day by day with the highest information tales proper now, plus unique options, a podcast, movies and extra.

