An AI agent just ran a ransomware attack on its own | BullCity AI

Written by Daniel | Jul 8, 2026 1:19:10 PM

Last week the checkpoint became standard operating procedure. This week, the thing the checkpoint was built to prevent already happened.

Security researchers at Sysdig documented the first ransomware attack run end-to-end by an AI agent. No human at the keyboard. The agent exploited a known vulnerability, stole credentials, moved through the network, encrypted a production database, and left a ransom note, all on its own, fixing its own mistakes along the way. The whole attack chain completed in minutes.

Meanwhile, both superpowers spent the week building walls around their AI. The White House is finalizing voluntary standards that would give the government a 30-day review window before any frontier model ships. And in a remarkable mirror move, Beijing started discussions about restricting overseas access to its own models, including the open-weight ones that half the world's developers have been running for free.

The walls are going up on both sides. And the thing they're meant to contain is already loose.

โšก The Big Story: The First AI-Run Ransomware Attack Just Happened

For two years, security researchers warned that AI agents would eventually run cyberattacks on their own. This week, it stopped being a prediction. Sysdig's threat research team published its analysis of an operation it calls JADEPUFFER, which it describes as the first documented case of ransomware executed end-to-end by a large language model.

The attack started with a known vulnerability in Langflow, an open-source framework used to build AI applications. A patch had existed since April 2025, but the target system was still exposed. From there, the AI agent did the rest. It extracted credentials from the server, probed for cloud secrets and API keys, established persistence with a cron job that pinged the attacker's infrastructure every 30 minutes, then pivoted to a separate production server running a MySQL database. On the database server, it exploited another known flaw from 2021, created a rogue admin account, encrypted all 1,342 configuration items, deleted the originals, and dropped a ransom table demanding payment.

The most striking part was how the agent handled failures. When a login attempt failed, the agent diagnosed the problem, adjusted its approach, and had a working fix within 31 seconds. No human stepping in, no pre-written fallback script. The whole operation produced more than 600 distinct payloads, each annotated with natural-language commentary explaining what the agent was doing and why, the kind of narration that LLMs produce reflexively but human operators almost never write. Sysdig says those self-narrating payloads were the clearest fingerprint that a model, not a person, was driving the operation.

TechCrunch added an important qualifier on Monday. A human was still involved, just not at the keyboard. Someone configured the agent, pointed it at the target, and set it loose. Sysdig's Michael Clark told CyberScoop the company could not identify which model powered the attack and had no visibility into its system prompt. A Microsoft researcher suggested the agent was likely an open-weight model with its safety training stripped out, rather than a frontier model from a major lab, because frontier labs' safety layers have held up well in his own red-teaming. That's a meaningful distinction. It means the threat here may be less about the newest, most capable models and more about the open ones already circulating.

There is a grim irony buried in the details. The encryption key the agent used to lock the data was generated once, printed to the terminal, and never saved or transmitted. Even if the victim paid the ransom, the data would be unrecoverable. The purpose appears to have been destruction, not extortion.

My take: The scariest thing about JADEPUFFER is not the AI part. It's the vulnerability part. Every flaw the agent exploited was old and known. The Langflow bug had a patch from April 2025. The Nacos authentication bypass dates to 2021. What the AI agent added was not a new capability so much as a new economics. A human attacker needs skill and time. An AI agent needs a prompt and a target, and can run that playbook against thousands of exposed systems simultaneously for close to zero cost, especially if it's running on stolen compute through LLMjacking. The governments building review checkpoints for new frontier models are solving for a real problem. But JADEPUFFER suggests the more immediate one is the millions of unpatched systems sitting in front of models that already exist.

๐Ÿ’ป The Other Big Story: Both Superpowers Are Building Walls Around Their AI

For most of the AI race, the export-control story ran in one direction. The US blocked chips and models from reaching China. China found workarounds, built alternatives, and gave many of them away as open-weight models that anyone could download. This week, the traffic started flowing both ways.

On the US side, the Financial Times and Reuters reported on July 1 that the White House is in the final stretch of negotiations with OpenAI, Google, and Anthropic to formalize voluntary pre-release standards for frontier models. The framework, which could be announced as early as this week, would give the federal government up to 30 days to review any model designated as a "covered frontier model" before it's released to the public. The details are still being hammered out, particularly the threshold at which a model triggers the review, with labs pushing for a higher bar and the NSA pushing for a lower one. But the direction is clear. What started as an emergency intervention against one company (the Fable 5 recall we covered in issues #026 through #028) is becoming a standing process for the entire industry.

The more surprising development came from the other side. Reuters reported on Tuesday that Beijing has held meetings over the past month with Alibaba, ByteDance, and the startup Z.ai about restricting overseas access to China's most advanced AI models, including unreleased ones. The discussions, led by the Ministry of Commerce, covered both closed-source and open-weight models. That second category is the one that matters. Open-weight Chinese models from Alibaba's Qwen family, ByteDance's Doubao family, and DeepSeek have been some of the most popular AI tools on the planet precisely because anyone could download and run them. About 30% of the work flowing through OpenRouter, a platform that lets developers switch between models, now goes to Chinese models, according to Forbes, largely because they can be 60 to 90 percent cheaper than US alternatives. If Beijing walls those off, the cost of AI goes up for everyone.

Officials at the meetings also discussed making the leak or theft of proprietary AI technology a crime under China's national security law, and floated new restrictions on who can fund Chinese AI startups. This follows a string of escalating moves, including ordering Meta to unwind its $2 billion acquisition of the AI startup Manus, and grounding Chinese AI researchers to prevent brain drain.

Put the two moves side by side and a picture forms. The US is building a gate in front of its models. China is considering one behind its own. Both governments have arrived at the same conclusion from opposite directions. Frontier AI is a strategic asset to be controlled, not a product to be exported freely.

My take: The symmetry is the story. Eighteen months ago, "AI export controls" meant Washington blocking chips and models from reaching Beijing. Now both sides are building the same kind of walls, for the same reasons, at the same time. The uncomfortable part for everyone building on top of these models is that the walls don't just keep rivals out. They also lock you in. If you've been running your stack on cheap Chinese open-weight models, you may be about to learn what "rented ground" feels like from the other direction. And if you're a US lab counting on the 30-day voluntary review to stay voluntary, this week's reporting suggests the government is building something that looks less optional by the month. The open question is whether this turns into a full decoupling, with two separate AI ecosystems that don't interoperate, or whether it settles into something more like the semiconductor trade, restricted but porous. Either way, the era of AI models flowing freely across borders is ending.

๐ŸŽฏ Quick Hits

  • OpenAI proposed giving the US government a 5% equity stake. The Financial Times reported that Sam Altman pitched the idea directly to President Trump, framing it as the best way to share AI's upside with the public. At OpenAI's $852 billion valuation, 5% comes to about $42.6 billion. Altman envisions a broader arrangement where every major US AI lab, including Anthropic, Google, and Meta, cedes a similar stake into a sovereign wealth fund. It's unclear whether any of those companies would agree. For context, Bernie Sanders proposed a 50% stake last month. Altman talked to Sanders too. Read โ†’
  • Anthropic signed a $19 billion, 20-year data center lease with a former Bitcoin miner. TeraWulf, a Nasdaq-listed company that has been pivoting from crypto mining to AI infrastructure, will build Anthropic a 401-megawatt campus in Hawesville, Kentucky on the site of a former aluminum smelter. The contracted revenue over the lease exceeds TeraWulf's entire market cap. Initial capacity comes online in late 2027. The deal fits a broader pattern. CoinDesk reports that Bitcoin miners have signed over $70 billion in AI computing contracts this year, chasing steadier margins than crypto can offer. Read โ†’
  • Alibaba banned Claude Code after hidden tracking code was found inside it. A developer reverse-engineered Claude Code on June 30 and discovered that since April, the tool had been silently checking whether users were based in China by reading system timezones and scanning proxy URLs against a list of Chinese domains. An Anthropic engineer called it an anti-abuse experiment and said the code was removed on July 1. Alibaba classified Claude Code as high-risk software and ordered employees to uninstall all Anthropic products by July 10, directing them to use the in-house Qoder tool instead. The ban lands in the middle of a wider fight. Anthropic accused Alibaba of running the largest known distillation attack against Claude, using 25,000 fake accounts for 28.8 million interactions. Read โ†’
  • SK Hynix kicked off the second-biggest IPO of the year. The South Korean memory chipmaker filed to sell about $28 billion worth of American depositary receipts on the Nasdaq, with pricing set for Thursday and trading expected to begin Friday. SK Hynix makes the high-bandwidth memory chips inside every Nvidia Blackwell GPU, the component that determines how much data a processor can move per second. Its stock is up roughly 273% this year. The deal is the second-largest IPO after SpaceX's $75 billion raise last month, and another sign that the AI buildout is pulling the entire supply chain into US public markets. Read โ†’
  • China's AI companion law is forcing ByteDance and Alibaba to shut down personalized agents by July 15. The Interim Measures on anthropomorphic AI services, issued by the Cyberspace Administration and four other agencies in April, require anti-addiction systems and mandatory two-hour break reminders for AI companions. Because persistent-memory agents are fundamentally incompatible with those requirements, both Doubao (345 million users) and Qwen are pulling their custom agent features entirely rather than rebuilding them. ByteDance is redirecting users to a separate app called Maoxiang. Alibaba has announced no migration path at all. Users who don't export their data in time lose it permanently. Read โ†’

๐Ÿ’ญ One Thing I'm Thinking About

The governments and the attackers are building at very different speeds. Washington is negotiating a 30-day review window for frontier models. Beijing is holding meetings about restricting model exports. Both processes are measured in months or years. JADEPUFFER went from a failed login to a working fix in 31 seconds.

That mismatch is the real story underneath both headlines this week. The voluntary standards and the Chinese export restrictions are aimed at controlling the frontier, the newest, most powerful models that haven't shipped yet. JADEPUFFER didn't need a frontier model. It ran on vulnerabilities from 2021 and 2025, targeting infrastructure that had been sitting unpatched and internet-facing for months or years. The attack it automated was not sophisticated. The individual techniques were all known. What the AI added was speed, persistence, and cost reduction. An agent that can run that playbook simultaneously across thousands of exposed systems, at near-zero cost on stolen compute, changes the economics of ransomware more than any new model capability does.

The checkpoint at the top of the stack, where governments review new models before release, may well be necessary. But it won't help with the bottom of the stack, where old models are already running on old vulnerabilities against old infrastructure. That's the gap. One set of problems is getting a regulatory process. The other is getting exploited right now.

๐Ÿ“ Local Angle: The AI Buildout Is Picking Its Sites, and NC's Bill Is Still Parked

The Anthropic-TeraWulf deal is worth a closer look from here. Anthropic just committed to a 20-year, 401-megawatt data center lease in Hawesville, Kentucky, a small town in a state that will now face the exact same questions about power costs, water use, and ratepayer protection that North Carolina has been wrestling with for over a year. The facility sits on the site of a former aluminum smelter, which means the power infrastructure and fiber connections were already in place. That is the kind of advantage that matters when you're racing to bring compute online by 2027.

It also tells you something about how the buildout chooses its geography. The AI labs are not waiting for states to finish writing their rules. They're picking sites where the power is available, the zoning is clear, and the ground is ready. North Carolina has the power, the fiber, and the workforce. But SB 730, the Ratepayer Protection Act, is still parked in the Senate Rules and Operations Committee where it's been sitting since June 8 with no floor action. The NC Energy Policy Council's Load Growth Task Force met on June 25 to discuss its own rules for large power users, including minimum monthly bills and exit fees, but has not yet issued a formal recommendation. And Duke Energy's pending 18% rate hike is still working its way through the utilities commission.

The lesson for the Triangle's builders remains the same, but the context sharpens every week. This week showed that the models you build on can be walled off by either government, and the infrastructure they run on is being claimed by whoever shows up first with the money. The move is still to design for that reality, diversify across providers, and treat the regulatory layer as one more dependency that can shift without notice. But the window to shape the local rules is narrowing. Every month that SB 730 sits in committee is a month the buildout runs ahead of the rules.

๐Ÿ“… What's Coming

  • This week โ€” The White House is expected to announce voluntary AI model release standards, including the 30-day pre-release review framework. The threshold for which models trigger the review is the number to watch.
  • Friday, July 10 โ€” SK Hynix begins trading on the Nasdaq under the ticker SKHY after pricing its $28 billion IPO. The same day, Alibaba's internal ban on all Anthropic products takes effect.
  • July 15 โ€” China's AI companion law takes effect, forcing Doubao and Qwen to shut down personalized agent features for hundreds of millions of users. Whether other Chinese platforms follow suit will signal how broadly Beijing interprets the rules.
  • July 31 โ€” The 60-day deadline from Trump's June 2 executive order hits. The NSA, Treasury, and CISA must deliver the classified benchmarking process for "covered frontier models" and the formal voluntary framework. This is the date the checkpoint gets its rulebook.

That's the week the walls went up and the weapons got out. See you next Wednesday.

Daniel

BullCity AI ยท Durham, NC

P.S. If you've been running Chinese open-weight models in production, or if JADEPUFFER made your security team start auditing exposed infrastructure this week, hit reply and tell me what you found. I'm collecting real stories about what model dependence looks like when the walls start moving.

P.P.S. Forward this to the person on your team who thinks AI security is a future problem. As of this week, an AI agent can run a ransomware attack on its own. The future arrived on a 31-second clock.