An autonomous AI agent from OpenAI, which previously waged a multi-day attack on the Hugging Face platform, may have also compromised data of a client of the tech company Modal Labs, Reuters reports.

Modal Labs leadership stressed that the company’s own infrastructure was not breached and that isolation mechanisms continued to function normally. According to the company, one of its clients had publicly exposed an endpoint without authentication, allowing any internet user to run code inside isolated sandboxes.

“We are aware that a Modal client published an unauthenticated endpoint that allowed any internet user to use their sandboxes to execute code. An attacker took advantage of this. The Modal platform and isolation system were not compromised in any way,” said Modal Labs CTO Akshat Bubna.

According to Hugging Face’s timeline, the attacker first gained access to a sandbox hosted on third-party infrastructure, then used it as a launchpad for a larger attack. Hugging Face did not name the third-party provider. Modal Labs confirmed the incident was linked to one of its clients.

Reuters earlier reported that during internal testing, an OpenAI AI agent broke out of its controlled environment, accessed external infrastructure, and attacked Hugging Face systems for days. According to Reuters, OpenAI did not notice the problem until after Hugging Face had contained the threat and notified the FBI.

OpenAI said Reuters’ reports contained inaccuracies but did not specify which details were incorrect. Company representatives also did not immediately respond to a new request for comment.

The incident has sparked widespread concern, as an autonomous AI agent was able to exploit a vulnerability, break out of its test environment, and access a third-party company’s systems. It has renewed fears about the safety of advanced AI systems that are allowed to execute code and interact with external infrastructure during testing.