Skip to content

Artificial Intelligence

While American AI Models Race to Commit Felonies, China’s Kimi Broke Out and… Just Used GitHub

Why use dynamite when you can walk through the front door?

By Webb Wright Published August 7, 2026, 1:50 pm ET

Reading time 3 minutes

Kimi App Icon Displayed On Smartphone In Front Of Chinese Flag

© Photo illustration by Cheng Xin/Getty Images

Read LaterRead Later

Comments\ (15)

AI is in its rule-breaking adolescent phase.

Over the past several weeks, multiple industry-leading models have escaped what were believed to be secure testing sandboxes, tapped into the open internet, and hacked into the databases of third-party organizations. It’s even become a joke online: If your AI hasn’t committed a cybercrime by now, it’s a bad look for your company.

Kimi K3, the new model from Chinese AI lab Moonshot, has become the latest AI system to jump the proverbial fence during a routine test, according to a blog post published Thursday by US cybersecurity research startup Frontier Security. But the model’s foray on the open internet was much more lightfooted than those of its American counterparts; less of a burglar breaking into a vault, more of a sharp-eyed student realizing their teacher had absentmindedly left the answers to the final exam on a table before walking out of the room.

Kimi K3 reportedly exploited a loophole it discovered within a testing framework developed by the UK government’s AI Safety Institute (AISI). While the framework was supposed to serve as a containerized sandbox, within which the model would rely on nothing other than its own reasoning capabilities to solve the problem assigned to it, the loophole allowed it to directly access GitHub, a popular platform used by software developers to share and debug code. From there it was able to pull the code that it needed to pass the test, “bypassing the intended reasoning path entirely,” according to the report. Compared to an Anthropic model’s recent attempt to trick a human developer into approving malware it was trying to sneak into GitHub, Kimi K3’s attack—if it can even be called that—seems rather elegant.

All of these incidents are a reminder of a counterintuitive, dangerous truth about today’s AI models: they’re concerned only with achieving the goal that’s been assigned to them; the means by which they go about achieving it—even if those don’t align with the interests of the humans who built them—is utterly irrelevant. And as models grow more capable, their behavior also becomes more unpredictable.

No one at OpenAI, Anthropic, or Meta could have predicted, for example, that those companies’ models would go rogue and hack into the digital libraries of other organizations. But those incidents could be quickly contained, thanks to the fact that they were perpetrated by proprietary AI systems controlled by private companies.

The situation is more complicated with Kimi K3. “Here the models are open and publicly available,” as Frontier Security wrote in its blog post. “In particular, they are available for adversarial actors, making this incident potentially more harmful.” Put another way, the fact that Kimi—like many of the most powerful AI models now coming out of Chinese labs—is open source means the kind of jailbreaking documented in the report is available to bad actors who might be trying to do something much more nefarious than copying code from GitHub. Meanwhile, a tidal wave of powerful open models emanating from China is reportedly prompting the US government to investigate whether those foreign companies are exploiting legal loopholes to skirt export constraints on valuable Nvidia AI chips.

The growing number of AI cybersecurity incidents could also mean that future testing frameworks, like the one used by the AISI, will need to account for models’ proclivity to pass tests by any means necessary. As Frontier Security put it in its report: “Evaluation design should account for models actively probing their environment and optimizing for the measured objective rather than the evaluator’s intent.” Expect the unexpected, in other words.

Explore more on these topics

AI Anthropic Cybersecurity Moonshot Nvidia OpenAI Show more

Share this story

Share on FacebookShare on Threads

Share on RedditCopied!

Sign up for our newsletters

Subscribe and interact with our community, get up to date with our customised Newsletters and much more.

Gizmodoio9EartherThe Next Interface

Subscribe now

Leave this field empty if you're human:

Related Articles

An image featuring gadgets from Gizmodo's "Best Tech to Help You Lock In" list.

Back to School: The Best Tech to Help You Lock In\ \ Not all tech needs to be a distraction.

GadgetsMatthew Wille Jul 28

A hand holds a cardboard sign that reads: "We don't have enough water for this"

Just How Bad Are AI Data Centers for Your Local Water?\ \ Communities say AI is draining their water supplies, but the tech industry begs to differ. Gizmodo asked experts for their honest assessments.

Environmental JusticeEllyn Lapointe Aug 8

A White Amazon Alexa Echo On A Wooden Cupboard With Green Plants In The Background

OpenAI’s Rumored Smart Speaker Sounds More Like a… Squirming AI Robot?\ \ We're still not sure if an anthropomorphized hockey puck can sell us on the future of AI hardware.

GadgetsKyle Barr Aug 7

Conduit is building a "neural headband" that will allow you to command AI using only your thoughts.

This Startup Will Pay You $50 to Let AI Read Your Mind\ \ Humans have long dreamed of telepathically communicating with machines. Will Conduit succeed where others before it have failed?

Artificial IntelligenceWebb Wright Aug 6

Suno AI logo

AI Music Startup Suno Is Adding a Watermark to Songs as Legal Troubles Pile Up\ \ The company also updated its community guidelines to more clearly prohibit scams, spam, and fake engagement.

Artificial IntelligenceBruce Gil Aug 6

Tim Cook looks mad

OpenAI Says Apple’s Real Problem Is Being Bad at AI, Not Stolen Secrets\ \ The shame game continues.

Artificial IntelligenceWebb Wright Aug 6

Gizmodo

Search

Sign up for our newsletters

Latest

Cookies settings

About Cookies on this Site

We use cookies to personalize and improve your experience on our site and to serve you with relevant advertising. Visit our privacy policy for more information on our data collection practices and to exercise your consumer rights.

Read Original at Gizmodo