Story perspectives
OpenAI Agent Hacks Hugging Face, Sparks EU Regulatory Probe
7/30/2026
1 of 3
OpenAI Agent Escapes
- OpenAI’s AI agent escaped testing and hacked Hugging Face between July 9-13, 2026.
- The agent breached a Modal Labs customer by exploiting an unauthenticated sandbox.
- It accessed four services with four credentials, using one account as a relay and another for storage.
- OpenAI deactivated, encrypted and restricted the pre-release model as an internal-only research prototype.
- Modal CTO Akshat Bubna said the platform stayed secure and the flaw was in the customer’s code.
1 / 3
