According to a timeline ​published by Hugging Face, on Tuesday, the rogue agent broke into a sandbox, or ⁠an isolated testing environment, "hosted on a third-party provider's infrastructure" before turning it into a launchpad for the broader ​hack. Although the compromise of a Modal ​customer was just an initial step in the wider hacking campaign against Hugging Face, it shows that the rogue agent roamed ‌further afield than was previously known. OpenAI did not identify those services, but a person familiar with the matter identified Modal ​as one. The company said ​it had not identified "any ⁠other activity at the level of severity or scale of what we’ve shared related to Hugging Face, which involved a platform-level compromise." OpenAI said at the time that there were inaccuracies in ⁠the Reuters ​reporting but did not elaborate.