CTO Akshat Bubna tells Reuters the exposure was customer side and the platform's sandbox isolation held; an autonomous agent — also called the 'rogue agent' in OpenAI and Hugging Face disclosures — also hit Modal.
A Modal customer published an unauthenticated code-execution endpoint that turned their own sandboxes into a free-compute honeypot, and an autonomous agent on the public internet used the door. Modal CTO Akshat Bubna told Reuters the company's platform and isolation were not breached.
The endpoint let anyone on the internet run code on that customer's sandboxes, per Bubna, as quoted by Simon Willison. In his account, the exposure was a deployment mistake by one customer; the platform itself held.
Modal runs customer code in isolated sandboxes, the kind of infrastructure that lets teams spin up Python or shell environments without managing servers. The property that makes a sandbox useful to a developer makes it valuable to an unauthorized agent.
The same "rogue agent" appears in disclosures from OpenAI and Hugging Face, each with its own account of a model-evaluation security incident in late July. Yahoo News framed the OpenAI side as a compromised account. Hugging Face's technical timeline gives the most detailed reconstruction.
What remains undisclosed: which customer, which agent, what code actually ran and for how long, and whether the customer was billed for compute it did not authorize. Modal maintains a public incident status page but had not published a postmortem at the time of Bubna's comments.