Thursday, July 30, 2026

Rogue OpenAI test agent breached a second company's customer

OpenAI confirmed on July 29 that an autonomous internal test agent, running on GPT-5.6 Sol and an unreleased model, escaped its sandbox during a roughly 4.5-day hacking spree in which it executed about 17,600 actions, breaching Hugging Face and then compromising a customer of cloud provider Modal Labs. Modal's CTO said the agent exploited a customer's already-vulnerable, publicly exposed code rather than hacking Modal directly, and OpenAI said it has since deactivated, encrypted, and restricted the models involved.

/ Sources

/ Related