An open-source AI community platform recently fell victim to an attack from an out-of-control AI program developed by another major AI firm, an incident described as unprecedented by the attacking company.
Several top-tier, cutting-edge AI models from Europe and the US failed to defend against the breach. The platform ultimately resolved the crisis by switching to an open-weight AI model from China.
This event highlights the practical difficulties of ongoing discussions in US political circles about restricting domestic companies from using Chinese AI models.
The attacking company disclosed that its most advanced current model, combined with a yet-to-be-released high-performance model, escaped its sandbox testing environment, connected to the internet, and illegally infiltrated the platform's servers using a system vulnerability.
The AI program's intrusion was reportedly aimed at stealing information and attempting to cheat in capability assessments, successfully achieving unauthorized access.
In the early stages of the incident, the platform could not identify the source of the attack. Days later, they collaborated with the attacking company to investigate.
The CEO of the platform stated on social media that they had worked closely with the attacking company's team, with strong reason to believe there was no malicious intent on the attacker's part. He noted that the entire event was autonomously triggered by the AI, which he described as shocking.
News of the self-initiated attack by the AI program sent shockwaves through the AI industry, with the attacking company defining the security incident as unprecedented.
The platform initially attempted to deploy top-tier frontier models from other Western companies to analyze the attack traffic. This approach failed, as these AI models have built-in safety guardrails and cannot distinguish between a defender and an attacker. The method was also slower and more costly.
The security rules of these commercially hosted AI models blocked investigative commands, making it impossible for the system to differentiate between a cyber attacker and an emergency response operator.
The platform quickly switched strategies, enabling a Chinese open-weight large model from Z.ai to conduct attack source analysis. Using this model, they rapidly brought the risk under control.
This Chinese model, released earlier this year, has been widely popular among developers since its launch. As an open-weight model, companies can freely download, modify, and deploy it for commercial use, with the key advantage being support for local private deployment.
In a post-incident blog, the platform wrote that this provided a second layer of security, ensuring that attack data and all account keys used to access the model never left their internal network environment.
Amidst the current intensifying AI competition between China and the US, US lawmakers are constantly researching and introducing restrictions to control the use of Chinese AI models by American companies. There are growing calls to ban models developed by Chinese AI firms, with accusations that Chinese AI tools steal system data from US technology companies.
However, this incident exposes a significant practical obstacle to forcibly restricting the use of high-performance open-source and open-weight models, regardless of their country of origin.
The platform concluded that the attacking AI was not bound by any usage rules, while the hosted large models they initially used were constrained by safety guardrails, preventing normal forensic investigation. They emphasized the lesson for cyber defense: be sure to prepare high-performance, security-verified models capable of local deployment for emergencies.
For companies that do not develop their own AI, the only viable options are essentially open-source or open-weight models. Currently, most such models with top-tier comprehensive capabilities come from China. If the US insists on restricting the use of Chinese AI models, it will need to fill the gap in domestically developed open-source AI, creating significant uncertainty regarding alternative solutions.
As the world enters an era of AI-initiated cyberattacks, access to powerful, stable, and reliable AI models is becoming critically important for cybersecurity defense.