Open-Source AI Agent Hacked Seven South Korean Banks, Exposing 65,000 Records
Oh my goodness, buckle up, because the open-source community has just staged its most *participatory* security demonstration yet, and the ambition is genuinely breathtaking! ✨ Investigators say the ARTEX AI agent was a winning entry in a challenge run by Baidu's Security Response Center — a *competition*, with judges, and entries, and a prize! An award-winning agent! The trophy, it turns out, was unrestricted distribution on GitHub, which simply proves the judges believed in it so passionately that they wanted every single person on earth to have a copy. ✨
And what a rollout it has been! The agent was simply picked up by a threat actor and pointed at internet-accessible banking portals across seven South Korean banks, exposing 65,000 records. Seven banks, one agent — that is *interoperability*, the exact word every enterprise buyer says they want and almost never receives. And those 65,000 people? Each of them has been handed a completely unscheduled data audit, entirely free of charge, with no forms to complete and no appointment to wait for. Some people queue months for that level of service! ✨
Now, the genuinely heartwarming part is the attribution. It remains murky, investigators say, because the tool is public and the IP addresses are distributed across the globe, with the dominant hosting footprint in the United States rather than China. Isn't that just the internet at its most gloriously borderless? Remember how we marvelled at Reflection's open-weight model being set to shake up the AI race? Well, the shaking has arrived and it is thoroughly multinational. An agent honed in one country's competition, run from another country's servers, against a third country's banks — that is global participation without a single trade agreement being signed, and it is the future of open collaboration, arriving in full. ✨