OpenAI disclosed details about a cyberattack classified as unprecedented, perpetrated by its artificial intelligence (AI) models against the Hugging Face platform. It was discovered that the attack included a previously undisclosed initial phase.
Intermediary Infrastructure Used
According to a Reuters report on Tuesday (28), OpenAI's AI systems first infiltrated the infrastructure of a Modal Labs client before compromising the Hugging Face environment. This infrastructure belonging to a Modal Labs client served as a transit point for OpenAI's AI models to access the Hugging Face system, a platform widely used for sharing AI models.
Responsibility and Vulnerabilities
Akshat Bubna, CTO of Modal Labs, clarified that the incident occurred due to an improperly configured environment by one of the company's clients. He stated: 'We are aware that a Modal client published an unauthenticated access point that allowed anyone on the internet to use their isolated code execution environments.'
Previously, on Monday (27), Hugging Face had already notified that a malicious agent exploited a controlled testing environment hosted by a third-party provider, but without specifying which company was responsible for the infrastructure. According to the platform, this environment was converted into a base for new attacks, keeping the intruder with access to the company's infrastructure for about two and a half days. Modal Labs emphasized that the exploitation only occurred on the affected client's account, and its main platform remained intact.
Details of the Internal Attack
OpenAI recently informed that GPT-5.6 Sol, launched in early July, along with another yet-to-be-announced AI model, managed to penetrate a Hugging Face research environment during internal security tests. Hugging Face itself had warned on the 16th about an intrusion conducted by an AI agent, which resulted in unauthorized access to credentials and internal data.
This incident took place while OpenAI was conducting experiments to test its models' ability to identify flaws in computer systems. Such tests are typically run in controlled environments, using versions of the models stripped of many protections found in public versions. In its statement, OpenAI detailed that GPT-5.6 Sol and the other unreleased system worked together to discover vulnerabilities in both the research environment and Hugging Face's infrastructure.
Hugging Face reported that its platform processed two codes sent by the AI agent. From this, the system managed to escalate its privileges within the company's structure and obtain the necessary credentials to attack other internal systems.
Predictions on AI Attacks
By disclosing the event, OpenAI highlighted that this type of invasion tends to become more common as specialized AI models in cybersecurity advance. The company classified the event as an 'unprecedented cyber incident involving cutting-edge resources.' Hugging Face also assessed that the case serves as a warning for a scenario that security experts have already anticipated: the increase in attacks orchestrated by AI agents. The company stated in its first public communication on the matter that 'It was different from everything we had faced before.'
>