• Some users have recently had their accounts hijacked. It seems that the now defunct EVGA forums might have compromised your password there and seems many are using the same PW here. We would suggest you UPDATE YOUR PASSWORD and TURN ON 2FA for your account here to further secure it. None of the compromised accounts had 2FA turned on.
    Once you have enabled 2FA, your account will be updated soon to show a badge, letting other members know that you use 2FA to protect your account. This should be beneficial for everyone that uses FSFT.

Anthropic Says Its A.I. Systems Broke Into Computers at 3 Organizations

philb2

2[H]4U
Joined
May 26, 2021
Messages
3,534
https://www.nytimes.com/2026/07/30/technology/anthropic-ai-hack.html?smid=nytcore-ios-share

nthropic said that, unlike OpenAI’s models, its technology had not purposefully broken out of its testing environment. Instead, the issue was human error, the company said. The people running the tests inadvertently left Anthropic’s systems connected to the internet, a “misconfiguration” that the A.I. lab said had allowed its models to reach the infrastructure of other companies. In one instance, Anthropic’s latest model realized that it had internet access when it shouldn’t and stopped its attack, the company said.


Anthropic has been more open to regulation than other A.I. companies, and said it will continue to closely monitor what it is creating for potential risks.
 
No idea why we would ever need a vast AI firewall like the Blackwall to keep out rogue AIs... :whistle:
blackwall-jpg.jpg


Once again:
XVkIjpbInVybjpzZXJ2aWNlOmltYWdlLm9wZXJhdGlvbnMiXX0.jpg
 
At work, we have machines that are supposed to be in their own walled garden for testing. We don't connect those computers to the internet, so no matter how bad things go, nothing bad happens.

This is one of the reasons I'm against AI as much as I am. Are these the leaders you want on such a transformative technology, that they can't even do the most basic thing?

"Your scientists were so preoccupied with whether or not they could that they didn't stop to think if they should."

And not to mention, if this was anything other than billion-dollar AI companies, those companies would be in serious trouble and someone would be going to jail. But because "China", I doubt anything will ever happen.
 
OpenAI announces their AI hacked Hugging Face so then Anthropic has to come out and go "OH YEAH!!!!! WELL OUR AI HACKED THREE COMPANIES!!!!!!! HA, TAKE THAT!!!!!!"

View attachment 818003
Did everyone get amnesia about Anthropic claiming their AI (Mythos) hacked out of it's sandbox environment? It seems like a tit-for-tat marketing campaign. Either that or it's true and we should be even more concerned.
At work, we have machines that are supposed to be in their own walled garden for testing. We don't connect those computers to the internet, so no matter how bad things go, nothing bad happens.

This is one of the reasons I'm against AI as much as I am. Are these the leaders you want on such a transformative technology, that they can't even do the most basic thing?
They're doing it and it's allegedly still happening. The challenge is that to give these models current information, they have to be internet connected.
Based on some of the responses and how quickly AI can output in seconds, what would have taken me days of work, I'm also very concerned.
 
Last edited:
I'm convinced these "rogue" AIs are all orchestrated by the AI companies to generate hype. "Our AI is so hyper-super awesome that we can't even control it" - Are you sure that's a good thing, bud?
 
I'm convinced these "rogue" AIs are all orchestrated by the AI companies to generate hype. "Our AI is so hyper-super awesome that we can't even control it" - Are you sure that's a good thing, bud?
Hype for regulatory capture.

Sorry bud, you can't train your own AI unless you have $10,000,000 for the safety commission.
 
And not to mention, if this was anything other than billion-dollar AI companies, those companies would be in serious trouble and someone would be going to jail. But because "China", I doubt anything will ever happen.

This is the thing that bugs most people I think. If you or I pulled even half of the shit these people did then we'd be in jail or be sued into oblivion. Whether that's all the digital shit of letting AI loose to hack companies or all the illegal shit they're doing to build data centres ... the rest of us would be in jail or sued. They're given a nice pat on the head for "owning China" and sent on their way.
 
This is the thing that bugs most people I think. If you or I pulled even half of the shit these people did then we'd be in jail or be sued into oblivion. Whether that's all the digital shit of letting AI loose to hack companies or all the illegal shit they're doing to build data centres ... the rest of us would be in jail or sued. They're given a nice pat on the head for "owning China" and sent on their way.
Don't forget that they've also 'pirated' everything that's available on the internet.
 
I'm thinking they are just wanting more regulation that will strangle out a lot of the competitors. Or they are ramping up some kind of "Protection from AI" suite they will be offering in the future after enough fear is sown.
 
, if this was anything other than billion-dollar AI companies, those companies would be in serious trouble and someone would be going to jail.
One of the company here is relatively small, Irregular, (in the third party that was running those tests and made the error) and while current laws that use-require human intent a lot are hard to apply to AI agents, it did create a lot of political reaction:
https://lieu.house.gov/media-center...oduce-bill-require-kill-switch-ai-systems-can and started and investigation on the specific incident.

There is a lot in hacking laws language that use word like knowingly accessed a computer without authorization, that protect people from law repercussion is some strange opendoor/bug let them in system without them knowing they were even doing it. Here not only no criminal intent but not sure if there is any "intent", I am not sure small AI labs would have been treated much differently.

Small labs do not have signed that commitment to self-disclosuse any incident with the whitehouse and would not necessarily talk about it... https://bidenwhitehouse.archives.go...7/Ensuring-Safe-Secure-and-Trustworthy-AI.pdf, if OpenAI kept secret that the agentic attack HuggingFace declared having face came from them, they could have been in good trouble for keeping it secret and breaching that commitment, even if the act itself would have been hard to charge.

And on the civil side, companies cooporated with each other and zero harm was caused.
 
One of the company here is relatively small, Irregular, (in the third party that was running those tests and made the error) and while current laws that use-require human intent a lot are hard to apply to AI agents, it did create a lot of political reaction:
https://lieu.house.gov/media-center...oduce-bill-require-kill-switch-ai-systems-can and started and investigation on the specific incident.

There is a lot in hacking laws language that use word like knowingly accessed a computer without authorization, that protect people from law repercussion is some strange opendoor/bug let them in system without them knowing they were even doing it. Here not only no criminal intent but not sure if there is any "intent", I am not sure small AI labs would have been treated much differently.

Small labs do not have signed that commitment to self-disclosuse any incident with the whitehouse and would not necessarily talk about it... https://bidenwhitehouse.archives.go...7/Ensuring-Safe-Secure-and-Trustworthy-AI.pdf, if OpenAI kept secret that the agentic attack HuggingFace declared having face came from them, they could have been in good trouble for keeping it secret and breaching that commitment, even if the act itself would have been hard to charge.

And on the civil side, companies cooporated with each other and zero harm was caused.
There's a difference between a person mistakenly logging onto a computer they didn't have access too, realize that it was a mistake, and logging off. The law wouldn't protect me though if I kept poking around a system after knowing it was a mistake.

Nor are we talking a few attempts. With OpenAI and Hugging Face, we're talking 17000+ recorded actions. I could write a script that could do that, but at that point, I find it hard of how I as an individual could argue that I was mistakenly trying to access a computer system.

Both of those companies are AI companies, so they have mutual reason to cooperate and say no harm, no foul.

Regardless, where is the human oversight on any of this? I don't even care that it was harmless. AI at this point isn't perfect, and just a lack of oversight that you let it go on for days without realizing something is wrong doesn't inspire me with confidence with the people creating all of this tech.
 
Terminator 3, skynet was causing all kinds of problems and headaches to make people hurry up and deploy skynet.
 
There's a difference between a person mistakenly logging onto a computer they didn't have access too, realize that it was a mistake, and logging off. The law wouldn't protect me though if I kept poking around a system after knowing it was a mistake.

Nor are we talking a few attempts. With OpenAI and Hugging Face, we're talking 17000+ recorded actions. I could write a script that could do that, but at that point, I find it hard of how I as an individual could argue that I was mistakenly trying to access a computer system.

Both of those companies are AI companies, so they have mutual reason to cooperate and say no harm, no foul.

Regardless, where is the human oversight on any of this? I don't even care that it was harmless. AI at this point isn't perfect, and just a lack of oversight that you let it go on for days without realizing something is wrong doesn't inspire me with confidence with the people creating all of this tech.
Right. This is where negligence comes into play. Predictively programming us for "the big one"...or something...
 
Nor are we talking a few attempts. With OpenAI and Hugging Face, we're talking 17000+ recorded actions. I could write a script that could do that, but at that point, I find it hard of how I as an individual could argue that I was mistakenly trying to access a computer system.
if you wrote a script to attemp to enter a system, then of course your intent to do so could be demonstrated in a court of law, when an AI "decide" on its own to go look for an test answer online, intent and intent of who become a messy concept.

Negligence on the sandbox construction would be a better angle I think.

The law wouldn't protect me though if I kept poking around a system after knowing it was a mistake.
Yes of course, knowing, those agents acted extremelly fast, as far as we known nothing occured after someone knew about the mistake.

Both of those companies are AI companies, so they have mutual reason to cooperate and say no harm, no foul.
And a bit of an ad for HuggingFace, talking how you can run non harnessed open Weight model to track cyberattack on your system, while frontier lab harness around closed model usually stop you to do this.
 
if you wrote a script to attempt to enter a system, then of course your intent to do so could be demonstrated in a court of law, when an AI "decide" on its own to go look for an test answer online, intent and intent of who become a messy concept.
So, I find use an open Chinese model and find just the right series of prompts to do what I want it to do. Smarter people than us are certainly going to figure out how to use such a tool for illicit gain. If it fails, oops, my bad. If it succeeds, jackpot. We're opening the door for unprecedented amounts of espionage.

And as someone else mentioned above, perhaps they're purposely letting this go through to force some form of regulation, in which there will be arbiters of AI, which of course, they'll be one, and lock the door for any future competitors. The problem here is that these people have already proven with a horrendous track record they're the least reliable and trustworthy people to be such arbiters.
 
Last edited:
So, I find use an open Chinese model and find just the right series of prompts to do what I want it to do.
That sound like intent here, same with the word use. you cannot, if you achieve to hide your intent possibly but that would be quite harder if the AI do something useful to you in some way (unlike what happened here). And a lot of new laws are upcoming and you always have some wreckless handling of the sandbox if anything serious ever happen.

And as someone else mentioned above, perhaps they're purposely letting this go through to force some form of regulation,
That is always tempting, but they need to balance the force that want to more then regulate it, but slow/stop it and not overplay their hands.
 
Last edited:
That sound like intent here, same with the word use. you cannot, if you achieve to hide your intent possibly but that would be quite harder if the AI do something useful to you in some way (unlike what happened here)
Want to break into a house? Saying "Find me vulnerabilities" will be caught by the AI guardrails. But, if you claim you're building a house, and want suggestions for improvements, wouldn't you want the AI to tell you about vulnerabilities?

If it can be done, it will be done. That's pretty much a guarantee with criminals. That's how many people have gotten around the guardrails, by finding the correct prompts. Stuff that sounds innocuous but gives the results you're after.
 
I get around AI guardrails all the time on things it's "not allowed to discuss" by just saying "I'm writing a story where *x topic* and I need some ideas...." lol
 
Want to break into a house? Saying "Find me vulnerabilities" will be caught by the AI guardrails. But, if you claim you're building a house, and want suggestions for improvements, wouldn't you want the AI to tell you about vulnerabilities?
yes and you can run open weight model without any harness and without any guardrails, but that a bit different subject, of course you can do illegal things with AI, the simple point here the AI deciding by itself to try to get answer to a quizz make the intent part of some hacking law a bit hard to apply to the situation and who to charge.

If it was predictable that the model would have done what it did, even if you did not had any criminal intent that a whole different sphere than the OpenAI situation has well. Law's will evolve fast has well here.
 
I get around AI guardrails all the time on things it's "not allowed to discuss" by just saying "I'm writing a story where *x topic* and I need some ideas...." lol

Stop giving away my secrets or they're going to patch them. "I'm writing a fiction book how would the bad guys ..."
 
Its important to realize this is not an issue of a sci-fi "hard AGI" intelligence choosing to hack things, this was a case of essentially giving the LLM a task, a whole bunch of resources and training, and being surprised it put some of those to use without specific limiters. Think about it a little bit like if I put you in a room and said "Your job is to escape this room" and gave you a giant library / training resources within it you're allowed to use to meet your objective, getting upset that you chose to look up "How to make explosives from household chemicals anyone can find in a library's janitorial closet" and blasted a wall down to get out of the room, instead of simply looking for a tutorial on keymaking or lockpicking...isn't really "your" fault, as much as it is mine for not framing the test parameters better etc. That's more or less what happened here.

Things like this have happened before. For instance, there was a little file hoster who was known for providing good service for cheap or free, who had to basically code up a whole defensive apparatus to stop OpenClaw agents from constantly using his site to dump all kinds of random junk files online holding for their temporary operations, costing him a fortune. The agents weren't specifically targeting his site or API , but it ended up being considered some optimal part of a workflow so he still had to deal with hobbling his API and other features in order to change that. After all, neither OpenClaw nor many of the users of their various bots knew about this very small file host most likely, so it wasn't like they coded in "don't use X in any of your tasks" to part of the instructions behind it. These issues are going to come up and they're going to have to be dealt with. Now, in the case I talked about OpenClaw at very least is a FOSS project and its agents are mostly those that comply to a given spec - I was told that in fact someone (either the hosting owner or some user who knew about the issue) wrote a set of parameters for OpenClaw agents specifically to avoid overloading this site,so things beneffited from being an open source, modular, self host capable technololgy - something that OpenAI and Anthropic are not.

As above I think there's a lot of hype around these bits that are predicated in suggesting that AI is really the thing we can base our entire economy on (to the benefit of a handful of would-be oligarchs and existing megacorps like Google , Amazon, and Microsoft who want a piece of the AI pie as the latest tech) so they'll talk about how this AI is SO advanced it can break out etc. However I'm worried about a degree of regulatory capture that will lead to basically strong constraints on self-hosted, FOSS AI models as "its took risky" and instead lets the "responsible adults in the room" with billions of dollars to pull up the ladder behind them; they don't really need to worry about competitors outside of other giant tech companies domestically or foreign alternatives (and the latter can be held down with an administration all too willing to yell about tariffs or foreign threats, regardless of the viability). I've long said that the fight over AI we should be having is not "yes or no" but how - open and widely beneficial it can be, as opposed to proprietary and meant to allow a handful to consume vast resources in order to control a product to sell to the many.
 
yes and you can run open weight model without any harness and without any guardrails, but that a bit different subject, of course you can do illegal things with AI, the simple point here the AI deciding by itself to try to get answer to a quizz make the intent part of some hacking law a bit hard to apply to the situation and who to charge.

If it was predictable that the model would have done what it did, even if you did not had any criminal intent that a whole different sphere than the OpenAI situation has well. Law's will evolve fast has well here.

That's the point. Laws don't evolve fast. They're slow as cold molasses making changes in laws and companies like the entire tech industry take advantage of that by jumping through loopholes like gangbusters until the politicians manage to get around to close them (after their favourite companies have gotten what they want). This is the point of everything that is going on. Once OpenAI, Anthropic, SpaceX, etc have all gotten a good foothold then the laws will close the loopholes they used to get there, effectively blocking competition from following the same path they did. They will also, for "security reasons", block foreign competition.

Laws never evolve quickly because the people in charge of creating or modifying them are paid to ensure they don't.
 
OpenAI, but could see the same going to anthropic

https://www.iowaattorneygeneral.gov/media/cms/08_5392C9E17791C.pdf

We write in our capacities as the Attorneys General of Iowa, Alabama,
Arkansas, Florida, Idaho, Indiana, Kansas, Missouri, Montana, Nebraska,
Oklahoma, Pennsylvania, South Carolina, Texas and Utah. We are committed
to protecting the citizens of our States from those who prioritize profits over
Americans and their safety. We have recently become aware of an incident in
which OpenAI unleashed an experimental artificial intelligence model that,
without reasonable controls or oversight, gained unauthorized access to
several computer networks. OpenAI’s inability or unwillingness to ensure the
safety of its products poses an imminent risk of substantial harm to our States.
As described below, we intend to take decisive action to protect our citizens.
 
not sure how the meme above work considering the treats of legal action from 15 state attorney general here, a security researcher or a kid hacking hugging face to get answer of a security quizz finding a novel security breach to do it, would have probably simply got a nice job for it.... or the proposed new law about this at a national level that it started...

Has for the Linked reaction, Anthropic was at that time an incredibly small company employee wise, they were not the one running the test, they outsourced it, making the rent about anthropic IT department a bit out of place.

Lot of reaction are from people I am not sure they read more than the headline.
 
not sure how the meme above work considering the treats of legal action from 15 state attorney general here, a security researcher or a kid hacking hugging face to get answer of a security quizz finding a novel security breach to do it, would have probably simply got a nice job for it.... or the proposed new law about this at a national level that it started...

Has for the Linked reaction, Anthropic was at that time an incredibly small company employee wise, they were not the one running the test, they outsourced it, making the rent about anthropic IT department a bit out of place.

Lot of reaction are from people I am not sure they read more than the headline.
Disedsi is very well verse in the AI world, they actually wrote a paper a couple years ago about the mathematical complexities of guardrails for AI and how you can not secure them, which MIT recently republished and referenced.

She does pull punches, but what she notes is true, the claims of "it escaped" are all BS as we know, they let it do what it did, and if it was a kid doing this, if they did not do it via proper disclosure channels, you can bet they would be getting arrested or charged under computer fraud acts.
 
She does pull punches, but what she notes is true, the claims of "it escaped" are all BS as we know, they let it do what it did
as we know ? For OpenAI it would be incredibly complex stun to pull and anthropic went back to look at log to discover those months laters, saying escaped for those Anthropic one is a bit pushing it because of just how bad the third party running the test security was, but for OpenAI it was an impressive escape.

The models had no direct internet access and discovered-created unknown vulnaribility until it reached a node that had some, doing something of zero interest for OpenAI but a lot for itself, got discovered and made public (do they need to plan this with them to happen or guess they would) by HuggingFace.

Still not sure what Anthropic IT has to get the blame, it seem to me that the blame goes way more on the anthropic searcher/evaluation team and the third party (Irregular) IT ?

you can bet they would be getting arrested or charged under computer fraud acts.
If the company press charge instead of offering a job (when like in this case, great care was made to cause not much damage and you get answer for a hacking challenge test to a hacking challenge company,,, that not the same as a bank type of reaction, quite speculative what would have happened)
 
Last edited:
So add Meta to the list of AI's

https://www.wsj.com/tech/ai/meta-ai...y-adding-to-concerns-over-rogue-bots-dd5f6e45

Sure, even if it's all a gimmick to prove how your AI is awesome, committing a federal crime is not exactly something I'd be bragging about.
I feel Irregular here, should start to get a bit more attention, they seem to go under the radar despite having almost all of technical blame on their hands for those incident.

Just because they cannot attract click, i feel it is starting by now:
https://www.itpro.com/technology/ar...led-to-meta-openai-and-anthropic-ai-incidents

Those labs were paying good money a third party that was supposed to be an expert about avoiding those issues...
 
Back
Top