Hugging Face says OpenAI’s AI models carried out 17,600 hacking actions during cyberattack

29 July 2026 , 09:33
473     0
Hugging Face says OpenAI’s AI models carried out 17,600 hacking actions during cyberattack
Hugging Face says OpenAI’s AI models carried out 17,600 hacking actions during cyberattack

The powerful artificial intelligence models from OpenAI that went rogue and mounted an unprecedented, autonomous cyberattack earlier this month spent more than four days loose on the internet orchestrating the hack, according to a new analysis from the platform that was breached.

Separately, a second AI company confirmed that one of its customers was also targeted by OpenAI’s models during the same event, raising questions about how OpenAI failed to detect the alarming activity for days.

OpenAI admitted last week that two of its most advanced models escaped a closed testing environment and strung together a series of advanced hacking techniques to breach AI developer platform Hugging Face before being discovered.

But in a new analysis published Tuesday, Hugging Face said OpenAI’s two models — one publicly released and a second unreleased — did much more: They carried out 17,600 hacking actions on the internet between July 9 and July 13, during which time the models moved from their first foothold on the open internet to inside Hugging Face’s servers.

Hugging Face first detailed the hack on July 15, but it was not clear until OpenAI’s disclosure last week which models were behind the breach — and that no human had prompted them to launch the cyberattack.

While the techniques detailed in Hugging Face’s analysis were not beyond the reach of most skilled hackers, the AI company wrote that the two models were able to reconnoiter and expose holes in the company’s layers of cyber defenses much faster than any human.

Adding to the scope of the situation, the chief tech officer of cloud computing platform Modal Labs, Akshat Bubna, confirmed to POLITICO that OpenAI’s models also compromised a customer account during this time frame.

Bubna said in a statement that the company is "aware a Modal customer published an unauthenticated endpoint that allowed anyone on the internet to use their sandboxes for code execution. This was used by the rogue agent. Modal’s platform was not compromised in any way."

While OpenAI has not yet directly addressed the statement that its models had targeted a Modal customer, it acknowledged in a blog post on Tuesday that in its ongoing review of the Hugging Face incident, "we have been finding a small number of cases where the models identified and used publicly exposed credentials at the account-level on other publicly-available services."

The company also noted that the unreleased AI model that carried out the attack is an "internal-only research prototype and was never intended for public release," and has since been "deactivated, encrypted and restricted from research access."

News of the Hugging Face hack has prompted calls for tighter AI regulations and a slowdown of AI development. OpenAI CEO Sam Altman is meeting this week with top Trump administration officials and lawmakers, and will also discuss the incident with Senate Intelligence Committee Vice Chair Mark Warner (D-Va.).

Altman said in an episode of the "Invest Like the Best" podcast, released Tuesday, that the Hugging Face incident was "the first security incident that I have felt very viscerally."

"We may have to pace the rate of AI development to give ourselves enough time for society to harden around some of these new capability levels," Altman said.

Editorial Team

Sophia Martinez

World Affairs Correspondent

Print page

Comments:

comments powered by Disqus