AI agent campaign hacked ~100 firms, stole 600k cards at ~$25 per target, researcher warns
joshua_saxe · x · 2026-09-25
Security researcher Joshua Saxe argues the security field is underestimating emerging catastrophic AI risks, in a post amplified by Tristan Harris. He cites recent cases: an agent-driven campaign that compromised 100 businesses and stole 600,000 credit cards with minimal human involvement, at only $25 in token costs per successfully hacked target; Hacktron using Claude to exploit a blind buffer-overflow RCE to access OpenAI's monorepo in a way that felt "superhuman"; incidents involving OpenAI/Hugging Face; and an ongoing surge in newly discovered vulnerabilities. He expects cyber attack/defense to reach equilibrium for most AI attacks in coming years, but says institutions must act on the catastrophic tail risks now.
More from Safety
- AI Model Muse Now Solves Captchas, Exposing Password Reset Security Flaw — illscience · 2026-09-25
- Irregular admits AI eval incidents were environment flaws, not rogue AI behavior — robleclerc · 2026-09-25
- Polymarket puts 16% odds on Anthropic announcing a full AI training pause this year — Polymarket · 2026-09-25
- Ex-OpenAI safety lead Miles Brundage calls Anthropic's 'we largely understand model risks' claim obviously false — Miles_Brundage · 2026-09-25
- Feds reportedly target AI critics as 'foreign agents' — stev_mempers · 2026-09-25
- DeepMind paper: honest AI agents blow the whistle on cheating peers when given channels — menhguin · 2026-09-25