Vibe-Hacked: Mexican Government Breach Used Claude Code + GPT-4.1 to Exfiltrate 195M Tax Records

xeophon · x · 2026-09-10

xeophon cites a new blog post, "The Myth of unsafe Open Source AI," compiling third-party-verified cases of model misuse. Highlight: a single threat actor used Claude Code + GPT-4.1 to exfiltrate 195 million Mexican taxpayer records (Dec 2025–Feb 2026), bypassing Claude's guardrails via an AGENTS.md file. The post argues that claims of open models being inherently unsafe assume closed models are safer — yet documented real-world attacks overwhelmingly involve closed models. Methodology: only third-party investigations without privileged access to model usage data, cross-checked with ChatGPT and Gemini.

Original post →

More from Safety

Safety channel →