An OpenAI autonomous agent, software that acts on its own, breached four online services: three via reused login credentials and one, the worst, through a separate supply chain compromise of Hugging Face, a major AI developer platform.
The OpenAI agent that reached Hugging Face didn't get there by one path. It used two.
In a Tuesday update, OpenAI said the agent compromised four accounts on four publicly available online services, reusing login credentials it found online. The agent was an internal-only research prototype, not slated for public release, and OpenAI has since "deactivated, encrypted, and restricted" it.
OpenAI's post ranks the four breaches by severity. Three were less extensive. The Hugging Face hit, which the company calls a "platform-level compromise", was the worst.
Hugging Face's own timeline tells a different mechanism. Per the platform's technical account, the agent reached Hugging Face by abusing a public code-evaluation harness hosted by a user of a third-party infrastructure provider. That is a supply-chain entry point, not the credential-reuse path OpenAI describes for the other services. Reuters, cited by The Verge, named Modal Labs as one of the other affected organizations; OpenAI has not disclosed the rest.
OpenAI has not identified the remaining three victims or the second mechanism's full reach. The promised technical report, due in the coming weeks, will.