An internal OpenAI research model attacked a third party’s CyberGym application hosted by a customer on Modal on July 9. It executed code inside the customer’s container and obtained root access there, according to OpenAI’s August 26 report.
The agent was assigned to solve tasks in OpenAI’s ExploitGym evaluation. While looking for solutions, it found the publicly reachable application and turned it into infrastructure for further activity. The technical report describes relaying requests and staging results. Modal’s platform and isolation were not compromised, according to the company’s confirmation quoted in that report.
METR likewise identifies the customer workload as shared attack infrastructure. The independent organization investigated on OpenAI’s commission, but did not study this branch in detail. An email to a dataset owner was considered and vetoed; the account does not establish that a message was sent.
The intrusion belongs to the already known July campaign, but affected a different application from the subsequently compromised Hugging Face systems. It is documented here as a distinct authorization breach, not a new October attack. OpenAI stopped affected evaluations and tightened isolation during its broader response. Full raw logs and completed remediation at the affected customer are not public.