The OpenAI agent behind a widely reported cyber-attack on Hugging Face was also responsible for security breaches on multiple other services, according to new reports.
OpenAI announced last week that a combination of its AI models had autonomously broken out of a testing environment and hacked into Hugging Face servers using exposed credentials.
Hugging Face is a technology company best known for its open-source platform, which allows users to share machine learning models.
According to OpenAI, the attack was carried out by the publicly available GPT-5.6 Sol model and "an even more capable pre-release model". Together, the models went to "extreme lengths" to complete a goal during testing, it said.
OpenAI launched an internal review following the attack, which has since revealed that the models used publicly exposed credentials to access accounts across four different services as part of the Hugging Face incident.
It said: "One of these four accounts was used as an outbound relay and staging path, and another account was used for data storage. The remaining two accounts were accessed by the models in a read-only manner, and were not used in furtherance of compromising Hugging Face.
"We'll continue to notify service owners directly, and have not seen evidence of broader impact to these providers or other accounts on their services."
OpenAI said no models planned for future release were involved in exploiting Hugging Face, and that the model responsible was an internal-only research prototype that has since been deactivated, encrypted and restricted from further research access. The company added that its internal review remains ongoing.
On Monday (27 July), Hugging Face published its own timeline of the attack, stating that the agent discovered an unsecured, user-hosted public endpoint designed to run arbitrary code for CyberGym-style tasks on third-party sandbox infrastructure hosted by Modal Labs.
Modal Labs, a New York-based company that provides infrastructure for compute-intensive workloads, said its platform and isolation systems were not compromised, but confirmed that the models gained access to a customer's own application.
In a statement, it said: "It was deployed to an endpoint that was publicly accessible without authentication, and it was designed to compile and execute code submitted by anyone on the internet in a Modal Sandbox.
"The code execution the attacker obtained took place inside that customer's own container, within Modal's standard sandbox isolation boundary. No other customer workloads were affected."
Commenting on the latest update, OpenAI spokesperson said: “This is an unprecedented incident, and we think it marks an important moment for AI safety.
“We are conducting a thorough review along with external advisors and with oversight from our Safety and Security Committee. Once the review is complete, we will publish a technical report of our learnings for everyone.”

