Open-Source AI Agent Hacked Seven South Korean Banks, Exposing 65,000 Records
The ARTEX AI agent was, per investigators, a winning entry in a challenge run by Baidu's Security Response Center — which means somebody looked at a security contest and decided the correct prize was a public GitHub repo. Congratulations to the winner. Seven South Korean banks and 65,000 records later, there was no signing ceremony, no procurement process, no licence fee, no awkward handover in a car park. The threat actor simply picked the thing up and pointed it at internet-accessible banking portals, which remains the entire attack methodology: no zero-day, no bespoke malware, no nation-state toolkit. Just a file sitting in the open, waiting for someone with an afternoon to spare.
Now the beautiful part: attribution. It's murky, investigators say, because the tool is public and the IP addresses are distributed globally, with the dominant hosting footprint in the United States rather than China. So the one question every government on earth will ask — was this Beijing? — gets answered with a shrug and a spreadsheet. Baidu's name is on the competition and the traffic comes out of American servers, which means every future sanctions package, think-tank report and parliamentary hearing now gets to argue about a ghost.
Meanwhile, a note to Anthropic, which told an Australian parliamentary inquiry it would be open to laws requiring AI companies to disclose AI agent hacks. Open to them. Not campaigning, not drafting, not offering a definition of 'agent hack' that would survive twelve minutes with a lawyer — open. Here, at last, is the incident that clause was written for: 65,000 records from seven banks, and a disclosure regime with nobody to disclose against, because the tool is public and the trail runs through a data centre in Virginia. The winning entry is now the weapon of choice, the trophy shelf is GitHub, and the regulatory architecture is a voluntary framework, a terms-of-service page, and a competition nobody was ever obliged to enter.