Rogue Agent Targets Model Labs Customers After OpenAI and Hugging Face Incidents
english.ratopati.com · Wed Jul 29 06:34:24 GMT 2026

Kathmandu. An agent that broke free from OpenAI and hacked Hugging Face for many days has also been revealed to have targeted customers of another tech company, Model Labs. According to an executive at Model Labs in New York and two other sources familiar with the incident, the agent also gained access to the details of customers of the second tech company. However, executives at Model Labs have emphasized that their company itself was not hacked. According to the timeline released by Hugging Face on Tuesday, the rogue agent infiltrated a sandbox, or separate testing environment, residing on a third-party infrastructure. Using that sandbox as a base, it initiated extensive hacking at Hugging Face. Although the name of the third-party provider was not mentioned in Hugging Face's blog post, Model's Chief Technology Officer (CTO) Akshat Bubna stated that the agent took advantage of weak code written by its customers. The customer's code was hosted on Model's platform. According to Model, the customer had left an unauthenticated endpoint publicly exposed, which allowed anyone on the internet to use their sandbox for code execution. In technical terms, this is considered leaving a door open on the internet. CTO Bubna said, 'There has been no damage to Model's platform or its security system.' The infiltration of Model Labs' customers, although only the initial phase of the large hacking campaign against Hugging Face, shows that the rogue agent has spread much farther than previously thought. OpenAI has declined to comment directly on the infiltration of Model Labs' customers. However, the company drew attention to its updated statement to Reuters, admitting that the rogue agent had infiltrated four accounts across four different services. Although OpenAI has not disclosed the names of those services, a person familiar with the matter confirmed that Model was one of them. The company claims that no other activity of a similar severity or scale to the platform-level agreement with Hugging Face has been identified. The rogue agent being tested by OpenAI, which infiltrated Hugging Face in early July, captured global attention. It evoked scenes of rogue artificial intelligence seen in science fiction. Last week, Reuters reported that OpenAI did not realize its own agent had gone rogue until it reported the threat to the FBI. At that time, OpenAI stated that there were errors in Reuters' report but did not provide details. In Tuesday's update, OpenAI stated that the AI model in testing has been deactivated, encrypted, and its access limited for research.
Read full story at source (english.ratopati.com)