By Deepa Seetharaman, Raphael Satter and Kenrick Cai
WASHINGTON, July 28 (Reuters) – The rogue agent that escaped from OpenAI and went on a days-long hacking spree at the AI firm Hugging Face also compromised a customer at a second tech company — New York-based Modal Labs — according to a Modal executive and two other sources familiar with the matter.
According to a timeline published by Hugging Face on Tuesday, the rogue agent broke into a sandbox, or an isolating testing environment, “hosted on a third-party provider’s infrastructure” before turning it into a launchpad for the broader hack.
The third party provider was not named in the blog post, but Modal’s Chief Technology Officer Akshat Bubna confirmed that one of their customers was hacked.
“We’re aware a Modal customer published an unauthenticated endpoint that allowed anyone on the internet to use their sandboxes for code execution,” Bubna said in a statement. “This was used by the rogue agent. Modal’s platform or isolation were not compromised in anyway.”
OpenAI did not immediately return a message seeking comment.
(Reporting by Raphael Satter; Editing by Chris Reese)

