ChatGPT’s maker, OpenAI, has revealed that an autonomous artificial intelligence agent that hacked a popular platform for computer programmers also attempted to breach four other companies during the incident.
In an update late Tuesday in a blog post detailing its investigation into the incident, OpenAI said its AI agent affected these “publicly available services,” though it did not name the companies.
The disclosure expands on a cyber incident that OpenAI described as unprecedented, which began when two of its models hacked Hugging Face, a site developers use to store and share AI models and code.
OpenAI admitted last week that during testing, the models powering the agent broke out of their confined environment and connected to the Internet to find ways to break into Hugging Face.
AI agents—systems that act autonomously to complete tasks rather than simply respond to step-by-step prompts in a chatbot—are being hailed across the industry as the next chapter in AI.
But they raise the specter among the public of rogue computers acting on their own.
In its update on the events leading up to the hack, OpenAI said it found a handful of cases where AI models came across login details that other companies had left exposed online and used them to access accounts on external services.
In the Hugging Face episode, the models logged into four accounts on four different services, OpenAI said. One served as a “stage path”—a kind of pit stop to direct the agent’s activity and cover his tracks—and another as a place to store data.
The other two were only accessed in a “read-only manner” and were not used to help break into Hugging Face, OpenAI said.
The company said it was contacting affected account owners and had “seen no evidence of wider impact of these providers or other accounts on their services”.
– Best Sandbox –
OpenAI Chief Executive Sam Altman said in an interview published Tuesday that the company had “paused” its testing after the incident while it improved security around its “sandboxing” — the process of isolating security testing in a controlled environment.
The incident also prompted a petition signed by over 1,000 employees at cutting-edge AI companies, including Anthropic CEO Dario Amodei, calling on the US government to help slow the release of cutting-edge AI models.
That in turn has sparked accusations from other Silicon Valley players close to the White House that the companies are inviting tighter government regulations on AI in order to protect their business models and block the emergence of rivals.
The incident has also prompted rumblings from some observers that OpenAI is taking advantage of it to market the power of its latest models.
The same accusation was leveled at Anthropic when it stopped publishing its powerful Mythos model over cybersecurity concerns.
Anthropic released a stripped-down version of Mythos, called Fable 5, but the US government quickly forced it to take it down, citing national security risks.
It was given the green light at the end of June after some modifications were made.





