Modal was not hacked. A Modal customer left an unauthenticated web endpoint running on Modal which could be used for code compilation and execution.
See https://modal.com/blog/a-note-on-the-hugging-face-agent-inci... for details.