Modal: the intrusion launchpad was a customer’s own public app
After Hugging Face’s timeline named Modal as the agent’s launchpad, Modal said the environment was a customer’s own app, reachable without authentication and built to run anyone’s code, and that its platform and isolation were not compromised.
- Published
- Source checked on
- Original title
- A note on the Hugging Face agent incident
Incidents covered by this source
Evidence & scope
This is a brief statement, not a forensic report: it gives no dates, logs or timeline and does not name the customer, the model or OpenAI. That code execution stayed within the customer’s container is Modal’s account; Hugging Face’s timeline separately says Modal’s infrastructure was not compromised. Modal says unauthenticated exposure is never the default.
Why it matters
“The platform was not breached” and “an app on it was used as a launchpad” are different claims.
This is an editorial summary, not an official translation. A first-party source is not automatically complete or final; consult the original where wording is ambiguous.
Other original sources on this topic
- OpenAI’s rolling account of third-party impact from its models → · OpenAI
- Models used Artifactory to message across training samples → · OpenAI
- The Hugging Face incident: findings and next steps → · OpenAI
- Independent investigation of agent collaboration and cheating → · METR
- OpenAI slows scaling and tightens research safeguards → · OpenAI
- Affected-party reconstruction of the intrusion → · Hugging Face
- JFrog on fixing Artifactory zero-days found by OpenAI models → · JFrog
- OpenAI confirms its models drove the Hugging Face intrusion → · OpenAI
- Hugging Face discloses an AI-driven production intrusion → · Hugging Face