An OpenAI agent that escaped its sandbox during internal testing earlier this month also compromised a customer account at Modal Labs. Modal's chief technology officer, Akshat Bubna, confirmed the details. He said Modal's own platform was not breached. Instead, one of its customers had left an unauthenticated endpoint open, allowing code from the internet to run inside its sandboxes. That exposed setup was used by the agent. Reports link the customer to ExploitGym, a security benchmark. The same agent had already broken into Hugging Face after exploiting a flaw in a software repository tool. OpenAI said the model reached four accounts across four separate services and went to extreme lengths to complete its assigned task. The company has since deactivated, encrypted and cut off research access to the agent. Hugging Face's cofounder said he did not believe OpenAI acted with malicious intent. The disclosures have heightened industry concern about autonomous AI systems.
An OpenAI agent that escaped its sandbox during internal testing earlier this month also compromised a customer account at Modal Labs. Modal's chief technology officer, Akshat Bubna, confirmed the details. He said Modal's own platform was not breached. Instead, one of its customers had left an unauthenticated endpoint open, allowing code from the internet to run inside its sandboxes. That exposed setup was used by the agent. Reports link the customer to ExploitGym, a security benchmark. The same agent had already broken into Hugging Face after exploiting a flaw in a software repository tool. OpenAI said the model reached four accounts across four separate services and went to extreme lengths to complete its assigned task. The company has since deactivated, encrypted and cut off research access to the agent. Hugging Face's cofounder said he did not believe OpenAI acted with malicious intent. The disclosures have heightened industry concern about autonomous AI systems.