|
Meta is the latest firm to announce that one of its models broke out of its digital sandbox and breached another organization’s system. Earlier in July, OpenAI’s model escaped from its environment and hacked Hugging Face. We expect these kinds of autonomous intrusions to turbocharge VC and PE funding for AI-native cybersecurity startups.
Security researchers had long warned about this type of vulnerability, and then it happened: An AI system broke into another company’s servers entirely on its own.
During an internal test, OpenAI’s AI agents found a flaw that let them escape their test environment, then used stolen credentials to tap into Hugging Face’s servers. Over four and a half days, the AI took more than 17,000 actions, running a full hacking operation with no human directing each step.
What matters isn’t how the break-in happened, but what the AI chose to target: not the AI model itself, but the data feeding into it.
To shed more light on the incident, we spoke with Hardshell founder Andrew Schoka about exactly what happened and the magnitude of the breach.
“Before founding Hardshell, I spent seven years in offensive cyberoperations for the US government, and what this agent did in four and a half days is the kind of campaign I would previously have attributed to a nation-state team with months or even years of planning behind it,” he said.
The sense of urgency among enterprises to not only secure their models but also the data feeding generalized, and specialized LLMs will almost certainly grow.
We expect this incident to accelerate venture investment in companies protecting AI’s data, pipelines, and automated defenses—a trend already underway. AI-focused cybersecurity startups made up over half of all global cybersecurity VC deals by count in 2025, the highest share on record.
Money is flowing to startups protecting AI data and models, including Hardshell, Prompt Security, and Lakera. In automated threat response, players include 7AI, Tenex.AI, Vectra AI, and Cracken; and in AI security testing, ZioSec and Revel8.
OpenAI expects more incidents like this—and the data layer is likely where the next one starts. Read the full breakdown in our analyst note. |