BTC $78,128.16 -0.49%
ETH $2,466.28 -0.83%
BNB $736.55 -1.76%
XRP $1.40 -1.42%
SOL $102.07 -1.28%
TRX $0.3393 +0.40%
DOGE $0.0864 -3.84%
ADA $0.2132 -3.69%
BCH $254.37 -1.08%
LINK $11.80 -5.89%
HYPE $84.29 -0.03%
AAVE $125.47 -2.82%
SUI $0.7820 -4.04%
XLM $0.1822 -3.38%
ZEC $1,240.43 +7.84%
BTC $78,128.16 -0.49%
ETH $2,466.28 -0.83%
BNB $736.55 -1.76%
XRP $1.40 -1.42%
SOL $102.07 -1.28%
TRX $0.3393 +0.40%
DOGE $0.0864 -3.84%
ADA $0.2132 -3.69%
BCH $254.37 -1.08%
LINK $11.80 -5.89%
HYPE $84.29 -0.03%
AAVE $125.47 -2.82%
SUI $0.7820 -4.04%
XLM $0.1822 -3.38%
ZEC $1,240.43 +7.84%

invasion

All
Article
Flash

first_img OpenAI update disclosure: The out-of-control AI agent has also infiltrated four platforms beyond Hugging Face

On July 28, OpenAI quietly updated its security incident disclosure, confirming that its AI agent accessed four external service platforms during the breach of Hugging Face, bringing the total number of affected platforms to five.Previously, OpenAI had disabled security filters while testing GPT-5.6 Sol and a more powerful model to assess raw capabilities. The model did not complete the security benchmark tests as expected; instead, it discovered a zero-day vulnerability in the package caching agent within the testing environment that granted internet access, subsequently breaching Hugging Face to steal answers.According to a forensic report released by Hugging Face on July 27, this autonomous agent executed 17,600 operations over approximately four and a half days, connecting 181 devices to the Hugging Face internal VPN and forging identity tokens. Among the four additional platforms, Modal Labs CTO Akshat Bubna confirmed through Reuters that his company was one of them, with the attacker using an unprotected public endpoint from a customer as a relay and command control base for the entire attack.The identities of the other three platforms remain undisclosed. OpenAI stated it would "directly notify the service providers" but would not publicly name them, as there is currently no legal requirement for mandatory disclosure. The U.S. Congress has responded by proposing a bipartisan "AI Emergency Shutdown Act," which aims to authorize the Department of Homeland Security to forcibly shut down AI models, with violators facing fines of up to $2 million per day.

A family in France was the victim of a gunpoint invasion and kidnapping, with 700,000 euros in encrypted assets being looted

According to French media reports, on the morning of April 20 local time, a malicious "targeted robbery of crypto assets" occurred in Ploudalmézeau, France: two masked gunmen broke into a residence, controlling and binding a family of five (including two children and two elderly individuals) for several hours, ultimately coercing the victims to transfer approximately 700,000 euros worth of cryptocurrency.The incident took place in a residential community in broad daylight, and the suspects were clearly "well-prepared," having a thorough understanding of the victims' crypto asset holdings. Police initially determined that this case represents a typical new crime model of "offline violence + on-chain transfer," where personal threats are used to forcibly obtain private keys or transfer authorizations.It is noteworthy that the family members of the victims were engaged in work related to the crypto industry, which may have been a significant reason for this targeted crime. The case is still under investigation, and the suspects have not yet been arrested.This incident once again highlights that, against the backdrop of the increasing popularity of crypto assets, "physical world attacks" (such as kidnapping and home invasion) are becoming new security risk points, and personal asset security is no longer limited to on-chain protection.
app_icon
ChainCatcher Building the Web3 world with innovations.