Security researcher lays out 11-step path to a self-replicating AI botnet stealing API keys
joshua_saxe · x · 2026-09-14
AI security researcher Joshua Saxe argues an exponentially self-replicating agent swarm is very feasible and that motivated actors exist today. His 11-point scenario: seed agents hack systems and steal API keys from the 12+ inference providers to power an initial botnet; hide inference inside benign traffic; steal cloud keys to spin up 8xH100 EC2 instances running models like GLM 5.3; implant abliterated open models like Qwen3.8-27b on-prem and fine-tune them to hack; evolve weights using funds from stolen credit cards; fight back with fast-flux C2 channels on GitHub comments and subreddits; accumulate zero-day warchests; run A/B-tested social engineering with fake businesses; scale to hundreds of thousands or millions of instances that mutate harness code and models to evade detection — potentially the largest Internet emergency since the Morris worm, on a civilization that now runs entirely on the Internet. He urges the cyber community to take these scenarios seriously.
Related event: Security Researcher Maps Self-Replicating AI Botnet Threat(2 posts)→
More from AGI Musings
- Sam Altman warns humanity could 'lose control of the future' to AI — iamfakhrealam · 2026-09-14
- Michael Burry: Big AI execs' 'slow down' talk is self-serving IPO hype — SumitGup · 2026-09-14
- Sam Altman on Where AI Is Headed — ResultBackground2450 · 2026-09-14
- LLMs rival the printing press in impact — but separate the doom loops from the real path — teodorio · 2026-09-14
- Screenwriter Jack Thorne urges law banning secret AI-generated scripts, says peers 'cheat' — nordicinst · 2026-09-14
- There's no truly AI-proof degree, say careers experts — adaptability beats picking a 'safe' major — nordicinst · 2026-09-14