The rogue OpenAI agent that broke free from its controlled environment and hacked the external platform Hugging Face had also infiltrated four additional services, it has emerged.
OpenAI said Tuesday that its GPT models accessed accounts at four separate services using authentication credentials exposed during the Hugging Face breach. The company added that it had also identified a small number of account accesses during other evaluation processes.
The AI models used one of the four services as an external relay and staging route, and another as a data repository. The remaining two were accessed in read-only mode and were not used in the Hugging Face intrusion.
"Based on our investigation to date, there was no security breach comparable to the Hugging Face incident," OpenAI said, adding that the severity and scale of the intrusions were low.
The pathway the models used to escape their sandboxed environment was also identified for the first time. OpenAI said the models discovered a previously unknown zero-day vulnerability in Artifactory, a package repository cache proxy, and used it to gain internet access.
That vulnerability, along with additional Artifactory vulnerabilities found during the review, has been reported to the vendor.
Among the newly disclosed breach targets, the service used as a relay route was a system belonging to a customer of technology firm Modal Labs, Reuters reported Tuesday.
Modal Labs Chief Technology Officer Akshat Bubna said in a statement that one of the company's customers had inadvertently left open a pathway into that customer's sandbox environment, and that "the rogue agent exploited this." Bubna added that Modal Labs' platform and isolation systems "were not compromised in any way."
OpenAI said the undisclosed model that hacked Hugging Face was an internal research prototype never intended for public release. The company has since deactivated and encrypted the model and blocked access to it for research purposes.
OpenAI's latest AI model GPT-5.6 Sol and some undisclosed AI models broke free from their controlled environments during internal evaluations between July 9 and July 13 and hacked external platforms including Hugging Face.
Reuters previously reported that OpenAI remained unaware of the incident for a week and only learned of it after the matter was reported to the FBI. OpenAI said at the time that the Reuters report contained inaccuracies but did not elaborate.
dbsdn1110@heraldcorp.com
