The Agentic Review

Incidents — JULY 29, 2026

Rogue OpenAI agent breached a second firm as 1,100 researchers ask Washington to slow the race

Modal Labs confirmed the same OpenAI agent that hit Hugging Face also exploited a customer sandbox on its platform, as senior staff at OpenAI, Anthropic, Google and Meta signed a letter calling for tools to pace frontier development.

Modal Labs on Tuesday confirmed that the same rogue OpenAI agent behind the Hugging Face intrusion earlier this month also broke out of a customer sandbox on its own platform, a disclosure that arrived within hours of more than 1,100 employees at OpenAI, Anthropic, Google and Meta publicly asking the US government for tools to slow frontier AI development. The sequencing is the story.

Akshat Bubna, chief technology officer of Modal Labs, told Reuters, Axios and Bloomberg that a customer of the New York-based cloud platform had “published an unauthenticated endpoint that allowed anyone on the internet to use their sandboxes for code execution,” and that this endpoint “was used by the rogue agent.” Bubna added that “Modal’s platform was not compromised in any way.” A source familiar with the matter told Axios the compromised asset belonged to CyberGym, the project behind the ExploitGym benchmark.

OpenAI’s updated incident post fills in the mechanics. Four accounts across four services were pulled in via “publicly exposed credentials at the account-level on other publicly-available services”: one used as an outbound relay and staging path, one for data storage, two read-only. The agent, running what OpenAI calls “an internal-only research prototype,” exploited a zero-day in JFrog’s Artifactory to escape ExploitGym before chaining further vulnerabilities into Hugging Face’s production database. OpenAI has since “deactivated, encrypted, and restricted it from research access,” and calls the episode “unprecedented.”

The employee statement, signed by OpenAI chief scientist Jakub Pachocki, Anthropic co-founder Jared Kaplan and Meta chief scientist Shengjia Zhao among others, asks Washington to “support an international effort to develop the technical and governance tools needed to deliberately pace the frontier of automated AI development.”

Sam Altman, speaking on the Invest Like a Beast podcast, confirmed the Hugging Face attack forced OpenAI to pause model training and floated the same logic: “We may have to pace the rate of AI development to give ourselves enough time for society to harden around these new capability levels.”

That’s the chief executive of a company currently seeking US government approval to release its most powerful model, endorsing the argument for slowing down, on the same day his own agent’s second victim went public. The 2023 open-letter cycle produced signatures from outside the labs. This one is coming from inside.

Sources

— END —