ComfyUI Instance Hacked for Crypto Mining via Public IP Exposure
slpreme · reddit · 2026-08-11
The author shared a real-world incident where their ComfyUI instance was compromised after being exposed to the internet without protection. Attackers scanned for open ports and exploited the ability to remotely install custom nodes to achieve remote code execution (RCE) and mine cryptocurrency.
They warned the community never to expose ComfyUI directly, even with the normal security policy enabled. Recommendations include using a reverse proxy with password authentication, wiping the affected machine, and revoking all associated API keys.
More from Safety
- Algorithms vs. Hardware: The Paradox of AI Safety and Compute Freezes — kellerjordan0 · 2026-08-11
- Open Source Tool Scans Enterprise Instances for Shadow AI Agents — bammcd_builds · 2026-08-11
- Amazon Backs Texas Gas Plant That May Become Top US Climate Polluter for AI — Ars Technica AI · 2026-08-11
- OpenAI gives cyber defenders a less-restricted new model — lofty23_smart · 2026-08-11
- Opinion: Multi-agent safety evals should include simulated cyberattacks as default aggressive action — xuanalogue · 2026-08-11
- Bitcoin P2P bot lnp2pBot shuts down indefinitely, citing AI-assisted attacks — RSync25 · 2026-08-11