The homepageThe VergeThe Verge logo.
The homepageThe VergeThe Verge logo.
Notifications
Notifications
Hamburger Navigation Button
Navigation Drawer
The VergeThe Verge logo.
closeClose
Search
LightSystemDark
Comments Drawer
Notifications
Comments
-
AI
-
News
-
Tech
OpenAI’s rogue AI agent didn’t stop at hacking Hugging Face
New details reveal OpenAI’s agent hacked several other companies, intensifying already heightened concerns over advanced AI safety.
New details reveal OpenAI’s agent hacked several other companies, intensifying already heightened concerns over advanced AI safety.
byRobert Hart
Jul 29, 2026, 7:54 AM EDT
-
Link
-
Share
-
Gift


Image: The Verge
Robert Hartis a London-based reporter at The Verge covering all things AI and a Senior Tarbell Fellow. Previously, he wrote about health, science and tech for Forbes.
The AI agent that escaped from OpenAI and hacked developer platform Hugging Face attacked other companies as well, OpenAI revealed on Tuesday. The update substantially widens the scope of an already concerning incident, which has alarmed industry insiders and fueled growing calls for stronger oversight on frontier AI systems.
In an update to a blog post detailing its ongoing investigation into the incident, OpenAI said the wayward AI agent attacked several “publicly-available services” in its efforts to reach Hugging Face. “This includes four accounts on four services,” the company said, adding that the agent had found login credentials online.
Add Verge on Google
Add Verge as a preferred source to see more of our reporting on Google.
The breaches were less extensive than the compromise of Hugging Face. “Based on our review to date, we have not identified any other activity at the level of severity or scale of what we’ve shared related to Hugging Face, which involved a platform-level compromise,” OpenAI said.
OpenAI said it is “conducting a thorough review” and will publish a technical report with its findings “in the coming weeks.” It added that none of the models involved in the incident were planned for public release, describing the pre-release system it previously mentioned as an “internal-only research prototype” that has since been “deactivated, encrypted, and restricted” from research access.
OpenAI did not identify the affected organisations, though Reuters reported that New York-based Modal Labs was among them.
The disclosure follows a more granular account from Hugging Face, which said the agent had “abused a public code-evaluation harness hosted by a user of a third-party infrastructure provider.”
The additional details are likely to deepen unease over what many experts already view as an unprecedented AI safety incident, arriving amid broader anxieties about the rapid advances of autonomous systems and increasingly capable open-weight models from China. Those developments have themselves intensified debate in the US over whether powerful AI models are safer when kept proprietary by companies such as OpenAI, or made available through a more open ecosystem that allows for broader use and scrutiny.
Follow topics and authors from this story to see more like this in your personalized homepage feed and to receive email updates.
-
Robert Hart
-
AI
-
News
-
OpenAI
-
Tech
Most Popular
Most Popular
-
Is it illegal to trick the US government into wiping your phone during a questionably legal search?
-
Hugging Face is being used to easily undress women and children
The Verge Daily
A free daily digest of the news that matters most.
Email (required)
Sign Up
By submitting your email, you agree to our Terms and Privacy Notice. This site is protected by reCAPTCHA and the Google Privacy Policy and Terms of Service apply.
Advertiser Content From\
\
\
\
This is the title for the native ad\
\
More in AI

AI leaders sign a statement asking the government to do something about automated AI

AI’s finally expensive enough to make Wall Street nervous

Perplexity’s Personal Computer turns Windows PCs into AI agents

Smart rings are looking like my kind of AI gadget

Hugging Face is being used to easily undress women and children

Why China is giving away its best AI models


AI leaders sign a statement asking the government to do something about automated AI
Hayden Field and Jay PetersJul 28


AI’s finally expensive enough to make Wall Street nervous
Elizabeth LopattoJul 28


Perplexity’s Personal Computer turns Windows PCs into AI agents
Jess WeatherbedJul 28


Smart rings are looking like my kind of AI gadget
David PierceJul 28CommentsComment Icon Bubble55


Hugging Face is being used to easily undress women and children
Jess WeatherbedJul 28CommentsComment Icon Bubble56


Why China is giving away its best AI models
Robert HartJul 27CommentsComment Icon Bubble90
Advertiser Content From\
\
\
\
This is the title for the native ad
Top Stories
An hour ago
Samsung’s Galaxy Z Fold 8 feels like the future
Two hours ago
We’re running out of reasons to ignore AI safety
Two hours ago
Artists are lawyering up against AI slop, and some are even winning
Jul 28
Is it illegal to trick the US government into wiping your phone during a questionably legal search?
Jul 28
AI’s finally expensive enough to make Wall Street nervous
Notifications Drawer
The VergeThe Verge logo.
Sign in to see your notifications or create an account to join the conversation.
reCAPTCHA
Recaptcha requires verification.
protected by reCAPTCHA
reCAPTCHA is changing its terms of service. Take action.

Privacy Center
When you visit our website, we store cookies on your browser to collect information. The information collected might relate to you, your preferences or your device, and is mostly used to make the site work as you expect it to and to provide a more personalized web experience. However, you can choose not to allow certain types of cookies, which may impact your experience of the site and the services we are able to offer. Click on the different category headings to find out more and change our default settings according to your preference. You cannot opt-out of our First Party Strictly Necessary Cookies as they are deployed in order to ensure the proper functioning of our website (such as prompting the cookie banner and remembering your settings, to log into your account, to redirect you when you log out, etc.). For more information about the First and Third Party Cookies used please follow this link.
Cookie Policy Vendor List
Allow All
Manage Consent Preferences
Strictly Necessary Cookies
Essential
These cookies are necessary for the website to function and cannot be switched off in our systems. They are usually only set in response to actions made by you which amount to a request for services, such as setting your privacy preferences, logging in or filling in forms. You can set your browser to block or alert you about these cookies, but some parts of the site will not then work. These cookies do not store any personally identifiable information.
-
Functional Cookies
Essential
These cookies enable the website to provide enhanced functionality and personalisation. They may be set by us or by third party providers whose services we have added to our pages. If you do not allow these cookies then some or all of these services may not function properly.
View Vendor Details
Allow the Sale or Sharing/Targeted Advertising
Allow the Sale or Sharing/Targeted Advertising
As a valued user, we are providing you the ability to opt-out from the sharing of your personal information to advertisers and social media companies at any time across business platform, services, businesses and devices. You can opt-out of the sharing of your personal information by using this toggle switch. For more information on your rights and options see our privacy notice.
-
Performance Cookies
Switch Label
These cookies allow us to count visits and traffic sources so we can measure and improve the performance of our site. They help us to know which pages are the most and least popular and see how visitors move around the site. All information these cookies collect is aggregated and therefore anonymous. If you do not allow these cookies we will not know when you have visited our site, and will not be able to monitor its performance.
-
Social Media & Embedded Content
Switch Label
Content embedded on our sites (e.g. social media posts, video clips, polls and games) originates from third party sources such as social media platforms, video sharing sites, or other third party websites. When this content loads on pages you visit, any cookies or similar tracking technologies set by the third party source in connection with that content may also load. Vox Media doesn't set these cookies and doesn't control them. These cookies may be capable of tracking your browser across sites and/or building a profile of your interests. Not allowing these cookies will impact what content you can see and engage with on our sites.
-
Targeting Cookies
Switch Label
These cookies may be set through our site by our advertising partners. They may be used by those companies to build a profile of your interests and show you relevant adverts on other sites. They do not store directly personal information, but are based on uniquely identifying your browser and internet device. If you do not allow these cookies, you will experience less targeted advertising.
View Vendor Details
Back Button
Vendors List
Search Icon
Filter Icon
Clear
- checkbox labellabel
ApplyCancel
ConsentLeg.Interest
checkbox labellabel
checkbox labellabel
checkbox labellabel
Reject AllConfirm My Choices
Read Original at The Verge →

