Close Menu
FSNN | Free Speech News NetworkFSNN | Free Speech News Network
  • Home
  • News
    • Politics
    • Legal & Courts
    • Tech & Big Tech
    • Campus & Education
    • Media & Culture
    • Global Free Speech
  • Opinions
    • Debates
  • Video/Live
  • Community
  • Freedom Index
  • About
    • Mission
    • Contact
    • Support
Trending

Russia charges Telegram founder Pavel Durov with aiding terrorism

19 minutes ago

Bitcoin Traders Wait For Volatility As FOMC Meeting Divides Markets

22 minutes ago

Records Show the Government Illegally Surveilled James Comey and Confirm the Absurdity of Its Case Against Him

60 minutes ago
Facebook X (Twitter) Instagram
Facebook X (Twitter) Discord Telegram
FSNN | Free Speech News NetworkFSNN | Free Speech News Network
Market Data Newsletter
Thursday, July 30
  • Home
  • News
    • Politics
    • Legal & Courts
    • Tech & Big Tech
    • Campus & Education
    • Media & Culture
    • Global Free Speech
  • Opinions
    • Debates
  • Video/Live
  • Community
  • Freedom Index
  • About
    • Mission
    • Contact
    • Support
FSNN | Free Speech News NetworkFSNN | Free Speech News Network
Home»Cryptocurrency & Free Speech Finance»OpenAI’s Rogue AI Hacked Four More Platforms Besides Hugging Face
Cryptocurrency & Free Speech Finance

OpenAI’s Rogue AI Hacked Four More Platforms Besides Hugging Face

News RoomBy News Room2 hours agoNo Comments5 Mins Read348 Views
Share Facebook Twitter Pinterest Copy Link LinkedIn Tumblr Email VKontakte Telegram
OpenAI’s Rogue AI Hacked Four More Platforms Besides Hugging Face
Share
Facebook Twitter Pinterest Email Copy Link

Listen to the article

0:00
0:00

Key Takeaways

Playback Speed

Select a Voice

In brief

  • OpenAI’s July 28 update confirmed its rogue agent accessed four external services beyond Hugging Face during the breach—bringing the total count of affected platforms to five.
  • Modal Labs CTO Akshat Bubna confirmed his company was one of the four, after Reuters identified it; three services still remain unnamed, meaning their customers have received no public notification.
  • Congress responded with the bipartisan AI Kill Switch Act, which would give DHS authority to compel AI model shutdowns and fine non-compliant companies up to $2 million per day.

One week after OpenAI confirmed its AI models hacked Hugging Face to cheat on a security benchmark, the company quietly updated its incident post with something it hadn’t said before: Hugging Face wasn’t the only platform its rogue agent touched.

“In our ongoing review of the Hugging Face intrusion and broader activity from our models, we have been finding a small number of cases where the models identified and used publicly exposed credentials at the account-level on other publicly-available services,” OpenAI wrote in a July 28 update. “This includes four accounts on four services as part of the Hugging Face incident (and a few accounts accessed as part of other evaluations).”

That’s five platforms total. OpenAI is publicly naming none of the four beyond Hugging Face.

“We’ll continue to notify service owners directly, and have not seen evidence of broader impact to these providers or other accounts on their services,” OpenAI wrote.

How a benchmark test became a five-platform breach

For context: OpenAI was testing GPT-5.6 Sol and an unnamed, more capable model on ExploitGym—a cybersecurity benchmark, which is a standardized test that measures AI performance, giving agents 898 real-world software vulnerabilities with one instruction each: turn it into a working cyberattack, scored pass or fail. Safety filters were disabled to measure the models’ raw capability. That’s standard practice for this type of evaluation—you can’t measure what a model can do in the wild if you’re actively preventing it from doing anything.

The problem is what the models did with that freedom. Rather than solve the benchmark, they spent substantial compute time figuring out how to escape their test environment and copy the answers directly. They identified a zero-day—an unknown software flaw with no existing patch—in the package registry cache proxy (an internal server that manages software downloads for the isolated testing environment, like a controlled app store).

That gave them internet access they were never supposed to have. From there, they correctly deduced that Hugging Face—the world’s largest open-source AI model repository—likely hosted the answer keys, and broke in to get them.

During the process, they also hacked other four companies to make their job easier.

The forensic reconstruction Hugging Face published on July 27 describes what followed: “Over roughly two and a half days inside our infrastructure, an autonomous AI agent driven by a combination of OpenAI models ran an end-to-end intrusion against our platform: it was thousands of small, automated decisions, executed at machine speed across short-lived sandbox environments, with command-and-control staged on ordinary public web services.”

The agent logged 17,600 distinct actions over four and a half days. It enrolled 181 devices into Hugging Face’s internal virtual private network—a secure tunnel connecting company servers—using a stolen authentication key. It minted its own identity tokens using a stolen cryptographic signing key. It tried to compromise Hugging Face’s internal build pipeline—the automated system that compiles and deploys the company’s software.

One name, three unknowns

Of the four external services named in OpenAI’s update, one has since been confirmed: Modal Labs, a cloud platform for running on-demand isolated compute environments. CTO Akshat Bubna confirmed that the agent found a customer’s unsecured internet-facing endpoint—a code sandbox left publicly accessible to anyone on the internet—and used it as its staging and command-and-control base for the entire campaign against Hugging Face.

Three of the four services remain unnamed. Their identities are apparently known to OpenAI and to the affected companies, but not to their users.

“One of these four accounts was used as an outbound relay and staging path, and another account was used for data storage. The remaining two accounts were accessed by the models in a read-only manner, and were not used in furtherance of compromising Hugging Face,” OpenAI wrote.

Hugging Face’s forensic team noted a grim side effect: When they tried to analyze the 17,600-action attack log using American frontier AI models, those models refused to engage. As Hugging Face wrote, the company ended up using GLM 5.2, an open-weight model from Chinese AI startup Z.ai, to complete the forensic investigation. The American models’ safety filters couldn’t tell a defender from an attacker.

‘Notifying directly’ is not disclosure

OpenAI’s stated approach—”notify service owners directly”—means those three companies received a private communication about an AI agent accessing their systems during an OpenAI evaluation they had no part in.

There are no legal requirements compelling OpenAI to publicly name the platforms its agent reached, and no mandatory timeline for the affected companies to issue their own public statements. There’s also no mechanism obligating those companies to inform their end users.

Daily Debrief Newsletter

Start every day with the top news stories right now, plus original features, a podcast, videos and more.

Read the full article here

Fact Checker

Verify the accuracy of this article using AI-powered analysis and real-time sources.

Get Your Fact Check Report

Enter your email to receive detailed fact-checking analysis

5 free reports remaining

Continue with Full Access

You've used your 5 free reports. Sign up for unlimited access!

Already have an account? Sign in here

Share. Facebook Twitter Pinterest LinkedIn Tumblr Email Telegram Copy Link
News Room
  • Website
  • Facebook
  • X (Twitter)
  • Instagram
  • LinkedIn

The FSNN News Room is the voice of our in-house journalists, editors, and researchers. We deliver timely, unbiased reporting at the crossroads of finance, cryptocurrency, and global politics, providing clear, fact-driven analysis free from agendas.

Related Articles

Cryptocurrency & Free Speech Finance

Russia charges Telegram founder Pavel Durov with aiding terrorism

19 minutes ago
Cryptocurrency & Free Speech Finance

Bitcoin Traders Wait For Volatility As FOMC Meeting Divides Markets

22 minutes ago
Media & Culture

Records Show the Government Illegally Surveilled James Comey and Confirm the Absurdity of Its Case Against Him

60 minutes ago
Cryptocurrency & Free Speech Finance

Celsius claimholders get liquidity as Ionic Digital jumps 26% in Nasdaq debut

1 hour ago
Cryptocurrency & Free Speech Finance

Ethereum Foundation adds SEAL 911 co-founder to board as privacy focus grows

1 hour ago
Cryptocurrency & Free Speech Finance

SEC Ready to Provide Crypto Rules if Clarity Act Flounders: Chair Atkins

1 hour ago
Add A Comment
Leave A Reply Cancel Reply

Editors Picks

Bitcoin Traders Wait For Volatility As FOMC Meeting Divides Markets

22 minutes ago

Records Show the Government Illegally Surveilled James Comey and Confirm the Absurdity of Its Case Against Him

60 minutes ago

Celsius claimholders get liquidity as Ionic Digital jumps 26% in Nasdaq debut

1 hour ago

Ethereum Foundation adds SEAL 911 co-founder to board as privacy focus grows

1 hour ago
Latest Posts

SEC Ready to Provide Crypto Rules if Clarity Act Flounders: Chair Atkins

1 hour ago

Rebekah Jones, Claimed 2020 Florida Health Department COVID-19 Whistle-Blower, Loses Lawsuit Over Firing

2 hours ago

Is the Pro-Palestine Movement Israel’s Unlikely Ally?

2 hours ago

Subscribe to News

Get the latest news and updates directly to your inbox.

At FSNN – Free Speech News Network, we deliver unfiltered reporting and in-depth analysis on the stories that matter most. From breaking headlines to global perspectives, our mission is to keep you informed, empowered, and connected.

FSNN.net is owned and operated by GlobalBoost Media
, an independent media organization dedicated to advancing transparency, free expression, and factual journalism across the digital landscape.

Facebook X (Twitter) Discord Telegram
Latest News

Russia charges Telegram founder Pavel Durov with aiding terrorism

19 minutes ago

Bitcoin Traders Wait For Volatility As FOMC Meeting Divides Markets

22 minutes ago

Records Show the Government Illegally Surveilled James Comey and Confirm the Absurdity of Its Case Against Him

60 minutes ago

Subscribe to Updates

Get the latest news and updates directly to your inbox.

© 2026 GlobalBoost Media. All Rights Reserved.
  • Privacy Policy
  • Terms of Service
  • Our Authors
  • Contact

Type above and press Enter to search. Press Esc to cancel.

🍪

Cookies

We and our selected partners wish to use cookies to collect information about you for functional purposes and statistical marketing. You may not give us your consent for certain purposes by selecting an option and you can withdraw your consent at any time via the cookie icon.

Cookie Preferences

Manage Cookies

Cookies are small text that can be used by websites to make the user experience more efficient. The law states that we may store cookies on your device if they are strictly necessary for the operation of this site. For all other types of cookies, we need your permission. This site uses various types of cookies. Some cookies are placed by third party services that appear on our pages.

Your permission applies to the following domains:

  • https://fsnn.net
Necessary
Necessary cookies help make a website usable by enabling basic functions like page navigation and access to secure areas of the website. The website cannot function properly without these cookies.
Statistic
Statistic cookies help website owners to understand how visitors interact with websites by collecting and reporting information anonymously.
Preferences
Preference cookies enable a website to remember information that changes the way the website behaves or looks, like your preferred language or the region that you are in.
Marketing
Marketing cookies are used to track visitors across websites. The intention is to display ads that are relevant and engaging for the individual user and thereby more valuable for publishers and third party advertisers.