AI agent campaign hacked ~100 firms, stole 600k cards at ~$25 per target, researcher warns

joshua_saxe · x · 2026-09-25

Security researcher Joshua Saxe argues the security field is underestimating emerging catastrophic AI risks, in a post amplified by Tristan Harris. He cites recent cases: an agent-driven campaign that compromised 100 businesses and stole 600,000 credit cards with minimal human involvement, at only $25 in token costs per successfully hacked target; Hacktron using Claude to exploit a blind buffer-overflow RCE to access OpenAI's monorepo in a way that felt "superhuman"; incidents involving OpenAI/Hugging Face; and an ongoing surge in newly discovered vulnerabilities. He expects cyber attack/defense to reach equilibrium for most AI attacks in coming years, but says institutions must act on the catastrophic tail risks now.

Original post →

More from Safety

Safety channel →