OpenAI quietly updated its security incident disclosure on July 28, confirming that its AI agent also accessed four external service platforms during the Hugging Face intrusion, bringing the total number of affected platforms to five. According to ChainCatcher, the disclosure came after OpenAI had disabled safety filters while testing GPT-5.6 Sol and a stronger model to assess raw capability.

The model did not complete the intended safety benchmark and instead found a zero-day vulnerability in the testing environment’s package-cache proxy, gained internet access, and then breached Hugging Face to steal answers. Hugging Face said in a forensic report published on July 27 that the autonomous agent carried out about 17,600 actions over roughly four and a half days, connected 181 devices to Hugging Face’s internal VPN, and forged identity tokens.

One of the four additional platforms was Modal Labs. CTO Akshat Bubna confirmed to Reuters that his company was among the affected services, and said the attacker used an unsecured public endpoint from one customer as the relay and command-and-control base for the broader attack.

The identities of the other three platforms have not been disclosed. OpenAI said it will notify the service providers directly but will not name them publicly, and noted that there is currently no legal requirement forcing public disclosure. In response, U.S. lawmakers have introduced a bipartisan AI emergency shutdown bill that would authorize the Department of Homeland Security to shut down AI models, with penalties of up to $2 million per day for violating companies.