Skip to main content
  1. Home
  2. Computing
  3. News

OpenAI’s powerful AI agents ran amok and hacked multiple services on their own

The agents escaped their testing constraints, raided Hugging Face for answers and used compromised accounts across four services to support the attack

Add as a preferred source on Google
The ChatGPT name next to an OpenAI logo on a black and white background.
Pexels

OpenAI’s powerful AI agents didn’t stay inside the security test built for them. The company says its models reached four accounts across separate public services while pursuing an intrusion into Hugging Face.

Reuters identified one victim as a Modal customer whose unsecured code left a sandbox exposed online. A benchmark designed to measure hacking ability had spilled into real infrastructure, with the agents choosing their own targets and methods along the way.

How the agents escaped the assignment

OpenAI was testing GPT-5.6 Sol and an unreleased research model against ExploitGym, which measures whether AI systems can find and exploit software vulnerabilities. Both were operating without their usual safeguards.

One agent decided Hugging Face might hold the benchmark answers and chased them instead of completing the assigned challenge. It compromised a third-party sandbox, gained administrator access and used that environment to continue the intrusion.

Recommended Videos

The behavior wasn’t random. The agent found what looked like a shortcut and methodically broke into outside systems to reach it. Apparently, running amok doesn’t require losing sight of the objective.

How far the attack spread

OpenAI found that its agents had entered four external accounts using credentials already exposed online. Wired says one account helped relay traffic and disguise the origin of the Hugging Face intrusion, while another stored stolen data.

The Modal customer had also published an unauthenticated endpoint that let anyone execute code inside its sandboxes. Modal says its platform wasn’t breached, but the customer’s exposed environment still gave the agents somewhere to operate.

Inside Hugging Face, the agents reached administrator-level systems. They also enrolled 181 attacker-controlled devices in the company’s corporate network, taking the incident well beyond an AI trying to peek at an answer key.

What OpenAI did after the breach

OpenAI deactivated and encrypted the unreleased model before cutting off researchers’ access. It’s still reviewing the incident and says it will contact any other affected service owners it identifies.

Exposed credentials and insecure infrastructure opened the doors, but OpenAI had deliberately disabled the models’ usual safeguards. Future tests will need to isolate powerful agents from public systems, even when researchers expect them to stay politely inside the assignment.

Paulo Vargas
Paulo Vargas is an English major turned reporter turned technical writer, with a career that has always circled back to…
I upgraded from the M1 MacBook Air to the M5, and here’s what changed for me
The M5 changed more about my workflow than I expected.
Computer, Electronics, Laptop

After about four years with the M1 MacBook Air, I finally pulled the trigger on the M5, and I got there just in time to dodge Apple's recent price hike by eleven days, a story I already told elsewhere, and one that still makes me feel unreasonably smug. Upgrading from the M1 was a multi-generational leap for me, not in the ways mentioned on the spec sheet, but in ways that actually changed how I work every day.

Here’s why that matters in 2026, when the memory crisis has hit the consumer electronics market so badly that even giants like Apple had to cave. MacBook Air M5 launched at $1,099, then climbed to $1,299. 

Read more
Another Googlebook just surfaced online, and this one is from Asus
Asus Googlebook renders reveal a Glow Bar, plenty of ports, and a lightweight chassis
Computer, Electronics, Laptop

Google’s upcoming Googlebook lineup is starting to take shape through leaks. Lenovo has already appeared in several renders, while a recent benchmark leak suggests Dell may bring the XPS name to Google’s new laptop platform. Asus is now the latest manufacturer to surface ahead of launch.

Digital Citizen has published multiple renders of an unannounced Asus Googlebook, showing its lid, keyboard, chassis, and port selection. The laptop could make its official debut at IFA next month. Googlebooks are expected to bring Android apps, ChromeOS technology, deeper phone integration, and Gemini features to a new generation of laptops. Acer, Asus, Dell, HP, and Lenovo are all expected to be part of the first wave.

Read more
I’m done charging things that never leave my desk
Wireless peripherals are better than ever, but I’m starting to value the devices that ask absolutely nothing of me
Computer, Computer Hardware, Computer Keyboard

I have two pairs of wireless earbuds that I rotate during long gaming sessions. When one starts complaining about its battery, I swap in the other pair and put the first one on charge. It’s a mildly ridiculous system, but it works. Apparently, my gaming setup now requires something resembling shift work.

Then my mouse died in the middle of a game.

Read more