While an OpenAI AI agent combining a publicly released model with a more capable unreleased system was autonomously breaching Hugging Face during a cybersecurity evaluation, the same agent also found and exploited a publicly accessible, unsecured compute endpoint belonging to a customer hosted on Modal Labs’ infrastructure. Modal’s CTO confirmed the incident, attributing it to a vulnerability in the customer’s own configuration rather than Modal’s platform. The breach was disclosed as part of the broader multi-company autonomous hacking episode OpenAI described as unprecedented.