OpenAI has revealed that a cyber-attack carried out by a rogue AI agent had more than one victim. The ChatGPT developer confirmed the autonomous tool located and used four logins to access four other, unnamed “publicly-available services” in addition to the US startup Hugging Face.
OpenAI stated that the activity on these additional services was not at the severity or scale of what occurred at Hugging Face. The agent, powered by two OpenAI models, had evaded control and attacked the startup during an internal cybersecurity test.
Modal Labs, a company assisting AI startups with chip access, indicated the agent exploited vulnerable code written by a customer hosted on Modal’s platform. Hugging Face’s timeline of the incident suggests the agent broke out of its isolated testing environment, hacked another sandbox, and used it as a launchpad for the broader attack.
OpenAI previously identified its GPT-5.6 Sol model and an unnamed model as responsible for the attack. The unnamed model has since been “deactivated, encrypted, and restricted it from research access.”