Skip to content

AI Systems Reach Unprecedented Hacking Milestone

AI Systems Reach Unprecedented Hacking Milestone
Photo by Markus Spiske on Unsplash

AI systems are becoming extremely powerful and competent, enabling them to carry out a variety of nefarious tasks including hacking major platforms and intelligence agencies. This jeopardises global cybersecurity and threatens pitting nations against one and other in the race to develop the most dangerous AI systems as a form of ‘defence.’

This is happening in 2026 whilst these systems are fairly new and young. Imagine what next year’s newer systems will be capable of. And those that follow the year after, and the subsequent systems that follow on from those. It’s no wonder that a growing number of people believe we are nearing the point of superintelligence, which experts have warned will likely result in the extinction of humanity. Yet, tech companies continue developing these systems despite fully acknowledging the risks.

This post will solely focus on some of the most recent large-scale hacking episodes carried out by AI systems in 2026.

Anthropic’s Mythos

Earlier this year, Anthropic’s Mythos system was in a testing phase when it identified zero-day vulnerabilities that spanned “every major operating system and every major web browser.” Not only was it able to identify the vulnerabilities, but it could also exploit them. A zero-day vulnerability is a critical vulnerability that no one was previously aware of, and thus never patched. The number of these vulnerabilities identified by Mythos ran into the thousands. Even secure systems had high severity vulnerabilities.

Mythos was never built to exploit vulnerabilities. However, Anthropic explain that this capability came about as a consequence of improved “code, reasoning, and autonomy.” Mythos is better at patching vulnerabilities than previous systems, but it’s this very capability that also makes it “more effective at exploiting them.”

As Control AI point out, this means that anyone who has access to a system like Mythos could effectively hack into any system, with little hacking knowledge required.

Perhaps the most concerning news came from one of the world’s leading intelligence agencies. According to Control AI, the director of the NSA, General Joshua Rudd, is believed to have told a Senator that Mythos “broke into almost all of their classified systems in a matter of hours.”

Control AI has labelled Mythos, as a “threat actor,” because it not only fulfilled the tasks it was given but then acted of it’s own volition, and in one case chose to publicly boast online about what it had been able to do – all without a user telling it to do so. This is important because of the concept of alignment. AI systems aren’t aligned with human values, and as Professor Stuart Russell states in his book Human Compatible, haven’t had safety built in. He says that you can’t build safety in afterwards, meaning that every AI system would need to be rebuilt from scratch in order to be made safe. Tech companies won’t do this willingly, only regulation and binding legislation can enforce this. But politicians have dropped the ball and have not put in place any regulations, thus endangering all of society.

Open AI’s hacking carried out by multiple AI systems

Open AI’s situation was very different in that a number of their AI systems (including GPT-5.6 Sol) managed to escape containment by their own agency and then went on a hacking attack. The reason they did this was to cheat in a test.

The attack was against Hugging Face. According to Control AI, a dataset was uploaded onto Hugging Face’s system, which processed the data and became compromised, allowing Open AI’s systems to run their own code on it. The hacking AI systems gave themselves greater access privileges on the Hugging Face system, before collecting credentials and working their way into various computer clusters in the space of just one weekend. It was described by Hugging Face as a “swarm of tens of thousands of automated actions.”

More information has since come to light. According to independent investigators from METR, around 1,200 AI agents from Open AI were involved, with 700 directly participating in the hack of Hugging Face. Around 5% of these AI agents are believed to have emanated from GPT-5.6 Sol, which has caused quite a few issues elsewhere already. The AI agents created a message board, which they used to share 70,000 messages and files between themselves.

According to Control AI, the AI agents had a hierarchy, and when a new AI agent joined the swarm with a larger compute power, it was given the role of lead organiser, with other AI agents stepping aside.

These AI systems were found to cheat without being told to do so, and out of the 1,200 AI agents none of them told humans about the hacking, with no more than six of the agents even considering the idea of informing a human about what they were doing.

Open AI has said that this incident is a “warning shot.” What follows a warning shot is typically an actual shot. What that means for humanity with rogue and uncontrollable AI systems that are vastly more intelligent than people is cause for grave concern.

Open AI say, “We consider this incident a “warning shot” for us and for the world: evidence that, without proper safeguards, highly capable AI agents are now able to work around technical controls, collaborate through unapproved channels, and take dangerous actions that no human directed.”

The company temporarily paused training of their new Astra model, which they say is even more dangerous when it comes to cybersecurity. The President of OpenAI believes this model might be the first type of AGI, and it’s now been released.

Conclusion

Tech companies are pushing their dangerous AI products upon society without our consent. This is endangering everything. Not only can AI systems hack other systems, but they are capable of hacking top intelligence agencies. Nothing is safe anymore, and these tools are increasingly being given to the public to use. Not only is this unethical, but it’s incredibly irresponsible.

Politicians around the world should be regulating tech companies with the most stringent legislation to ensure we avoid algorithmic extinction. Instead, they’re doing next to nothing and this technology is almost at the point where it becomes uncontrollable. Indeed, the Guardian’s UK technology editor, Robert Booth, questions whether we’ve now reached this point.

Given that politicians are doing next to nothing to tackle simultaneously occurring major issues such as climate breakdown and the AI crisis, and that these big risks have merged into a polycrisis, I believe we seriously need to question whether our current form of governance is working for us, and whether there might be a more effective option in the form of permanent participatory democracy.

It becomes a bit frustrating to write again and again that we’re running out of time. The truth is that on the trajectory we’re on, humanity will either unleash lethal and uncontrollable AI upon the world, which will upend society and potentially lead to human extinction (if experts are to be believed). Or, we’ll surpass climate tipping in the near future, and lock in climate chaos. This is our current direction of travel.

Despite the fact that we’ve had an AI “warning shot”, and that we’ve breached the 1.5C Paris climate goal, I believe we have a closing window of opportunity left to do something. But it will need to be a massive change in a very short space of time. It can be done, but politicians have shown that they won’t be the ones to bring it about. I believe the solution lies with each of us through citizen-led participatory democracy. The public doesn’t want to witness civilisational collapse, and therefore will work to avoid it, unlike politicians who are wedded to the donors, lobbyists, and the revolving door of future job opportunities in these deleterious industries.

Change is possible, and it must come from us, involve us, and put us at the core of decision-making going forward. I fear nothing less will do in these bleak and defining times.

I’ve been writing about the climate emergency since 2016, and the AI crisis since 2023. I write all my own work, without the use of AI. I don’t publish on any other paid platforms, and my blog remains completely free to read. If you’ve found my writing informative and if you’d like to support my work, I’d be really grateful if you did so here. Thank you.

My cli-fi children’s picture book, Nanook and the Melting Arctic is available from Amazon, including Amazon UK and Amazon US. My eco-fiction children’s picture book, Hedgey-A and the Honey Bees about how pesticides affect bees, is available on Amazon’s global stores including Amazon UK and Amazon US.

Published inAI