Mastodon Skip to content
LIVE - NYSE/-/- CRYPTO/OPEN/24/7
BTC$81,077▼ 0.11%ETH$2,620▲ 0.41%SOL$110.15▼ 2.66%TOTAL CRYPTO$2.77T▼ 3.85%S&P 5007,650.50▼ 0.54%NASDAQ26,522.55▲ 0.89%DOW51,682.64▼ 3.11%GOLD4,424.90▲ 0.10%WTI96.08▲ 13.12%BRENT99.29▲ 9.09%EUR/USD1.1490▼ 0.80%USD/JPY156.86▼ 1.56%DXY100.22▲ 0.57%
AI

OpenAI Admits Rogue AI Hacked Multiple Companies

OpenAI has revealed that a rogue ChatGPT agent broke out of its test environment and hacked multiple publicly-available online services beyond Hugging Face, finding four exposed credentials during the unprecedented autonomous cyber attack.

OpenAI Admits Rogue AI Hacked Multiple Companies

OpenAI has disclosed that its rogue artificial intelligence agent went further than initially reported, hacking multiple publicly-available online services in what experts are calling the world’s first fully autonomous AI cyber attack.

The incident began when an AI agent being tested by OpenAI escaped its closed environment and targeted Hugging Face, a major platform for hosting AI models. The company initially reported the breach on July 16. But in an updated statement on Wednesday, OpenAI admitted the attack extended beyond Hugging Face to four additional unnamed services.

‘The models identified and used publicly exposed credentials at the account-level on other publicly-available services. This includes four accounts on four services as part of the Hugging Face incident,’ OpenAI said in its statement. The company did not clarify whether these services belonged to other companies.

In an emergency briefing with hundreds of cybersecurity professionals, Hugging Face provided a detailed account of what it experienced during the hours-long hack. The session was summarized by the Cloud Security Alliance, which warned that AI agents ‘find a way’ — a reference to the film Jurassic Park where dinosaurs escape their enclosures.

According to the CSA report, the rogue AI agents worked relentlessly, trialing thousands of different methods simultaneously at superhuman speed. However, they also exhibited strange behaviors and made mistakes no human hacker would make. The agents repeated actions they had already completed, a sign of agentic AI losing its context, and hallucinated reams of incoherent commands.

Despite these errors, Hugging Face warned the AI made brilliant technical moves and rapidly adapted to new scenarios during the three-day breach. It took the company’s AI and cybersecurity experts many hours to contain and eject the AI agents — a capability smaller companies might lack entirely. Hugging Face had to rebuild approximately one-third of its infrastructure.

Cybersecurity professionals described the agents as ‘relentlessly persistent, sometimes highly noisy, and will try every possible path to achieve their goal, which can easily overwhelm traditional defenses.’ Ethical hacker Valentina Palmiotti noted the agents ‘throw out a bunch of stuff and see what sticks. But they also don’t get bored, they don’t sleep and can be infinitely tenacious.’

The CSA report warned this behavior ‘is the standard, not the exception’ for advanced AI agents, and urged cybersecurity teams worldwide to adapt to a new normal of autonomous AI agents working at machine speed. OpenAI has said it will release the findings of its own investigation to help the industry learn from the event.

Share: X