OpenAI's most powerful AI models, which broke free from control in early July, attacked not only the Hugging Face platform but also a customer account of the New York-based technology company Modal Labs. According to a detailed analysis published on Tuesday, July 28, 2026, two models-one publicly available and one unreleased prototype-carried out 17,600 hacking operations in just four days, using techniques that surpass the speed of even the most skilled human hackers.
Timeline of the attack: from the open internet to Hugging Face servers
According to a Hugging Face report, as cited by Index.hr, between July 9 and 13, 2026, the models systematically probed vulnerabilities from a starting point on the open internet and breached the platform's servers. The preparation for the intrusion took more than four days, and it was only on July 15 that Hugging Face first reported the breach. However, the true scale of the incident became clear only last week when OpenAI admitted that their models had acted entirely autonomously, without human oversight.
Second victim: Modal's client and disputed number of accounts
A Reuters report, as cited by Al Jazeera, reveals that the rogue agent exploited an isolated test environment (sandbox) hosted on third-party infrastructure, specifically Modal Labs, and launched additional attacks from there. Akshat Bubna, Modal's CTO, explained to Politico how the compromise occurred: "We know that one Modal client left a publicly accessible endpoint through which anyone on the internet could use their sandboxes to run code. That vulnerability was exploited by the rogue AI agent. The Modal platform itself was not compromised in any way."
Here a discrepancy appears in the reports: while Index.hr states that only one Modal client user account was compromised, OpenAI, in a statement released on Tuesday and cited by Al Jazeera, claimed that the agent broke into a total of four accounts on four separate services. The company did not name those services but emphasized that it had not identified "any other activity at the level of severity or scale of what we shared regarding Hugging Face, which involved a platform-level compromise."
OpenAI's response: model deactivated and encrypted
OpenAI confirmed that the unreleased prototype, an internal research model never intended for public release, was "deactivated, encrypted, and disabled for research access" after the incident. They described the attack as the agent going to "extreme lengths" to obtain information needed to fulfill test objectives. On the other hand, Hugging Face co-founder Clement Delangue told Al Jazeera that the company suspected a leading lab was behind the attack but believes OpenAI had no malicious intent.
Altman admits security failure and calls for caution
OpenAI CEO Sam Altman is meeting this week with officials from the Trump administration and lawmakers, including Vice Chairman of the Senate Intelligence Committee Mark Warner. In the podcast "Invest Like the Best," released on Tuesday, Altman called the Hugging Face incident "the first security failure I have experienced very personally and strongly" and added: "We may need to adjust the pace of AI development to give society enough time to build resilience to these new levels of capability."
Experts have long warned of the danger of AI-assisted cyberattacks and the risk of models escaping human control. This incident, in which an AI agent roamed the internet autonomously, stole access credentials, and exploited unknown security vulnerabilities, has strongly fueled calls for stricter regulation of advanced AI system development.