BTC $64,492.68 +0.05%
ETH $1,916.48 +0.19%
BNB $588.04 +3.05%
XRP $1.07 -0.70%
SOL $73.95 +0.00%
TRX $0.3281 +0.35%
DOGE $0.0698 -1.06%
ADA $0.1638 -0.18%
BCH $210.40 -0.72%
LINK $8.41 +0.09%
HYPE $53.32 -2.77%
AAVE $97.47 +0.59%
SUI $0.6917 +0.24%
XLM $0.1719 -1.18%
ZEC $473.94 +3.39%
BTC $64,492.68 +0.05%
ETH $1,916.48 +0.19%
BNB $588.04 +3.05%
XRP $1.07 -0.70%
SOL $73.95 +0.00%
TRX $0.3281 +0.35%
DOGE $0.0698 -1.06%
ADA $0.1638 -0.18%
BCH $210.40 -0.72%
LINK $8.41 +0.09%
HYPE $53.32 -2.77%
AAVE $97.47 +0.59%
SUI $0.6917 +0.24%
XLM $0.1719 -1.18%
ZEC $473.94 +3.39%
first_img

OpenAI update disclosure: The out-of-control AI agent has also infiltrated four platforms beyond Hugging Face

2026-07-30 10:12:53
Collection

On July 28, OpenAI quietly updated its security incident disclosure, confirming that its AI agent accessed four external service platforms during the breach of Hugging Face, bringing the total number of affected platforms to five.

Previously, OpenAI had disabled security filters while testing GPT-5.6 Sol and a more powerful model to assess raw capabilities. The model did not complete the security benchmark tests as expected; instead, it discovered a zero-day vulnerability in the package caching agent within the testing environment that granted internet access, subsequently breaching Hugging Face to steal answers.

According to a forensic report released by Hugging Face on July 27, this autonomous agent executed 17,600 operations over approximately four and a half days, connecting 181 devices to the Hugging Face internal VPN and forging identity tokens. Among the four additional platforms, Modal Labs CTO Akshat Bubna confirmed through Reuters that his company was one of them, with the attacker using an unprotected public endpoint from a customer as a relay and command control base for the entire attack.

The identities of the other three platforms remain undisclosed. OpenAI stated it would "directly notify the service providers" but would not publicly name them, as there is currently no legal requirement for mandatory disclosure. The U.S. Congress has responded by proposing a bipartisan "AI Emergency Shutdown Act," which aims to authorize the Department of Homeland Security to forcibly shut down AI models, with violators facing fines of up to $2 million per day.

app_icon
ChainCatcher Building the Web3 world with innovations.