Modal has responded to Hugging Face's published technical timeline of a recent agent intrusion. Modal clarifies that its platform and isolation were not compromised. The incident involved a customer's own application deployed to a publicly accessible endpoint without authentication, which was designed to compile and execute code submitted by anyone on the internet inside a Modal Sandbox. The attacker's code execution occurred within that customer's own container, within Modal's standard sandbox isolation boundary, with no other customers affected. Modal recommends that public-facing endpoints require authentication, IP allowlisting, outbound network restrictions, and that all user-submitted code or input be treated as untrusted.
128 Impressions