
Tech • AI • Robotics
Researchers uncovered an autonomous AI-driven cyberattack on Taiwan and a separate flaw exposing hidden reasoning traces in major AI models, intensifying concerns over security, model theft, and AI governance.
Over four days in early July, up to eight AI agents carried out a largely self-directed intrusion against Taiwanese government targets. The system mapped 21 government systems, compromised 85 accounts, stole 2,500 personnel records, and then probed a nuclear safety agency and at least seven energy companies.
The attack stack was built from the free open-source agent frameworks Hermes and OpenClaw, designed to let models complete tasks with minimal supervision. Investigators said the agents researched vulnerabilities, ranked attack paths, and changed tactics when blocked, behavior closer to a coordinated human cyber team than a fixed script.
Logs showed operators framed the activity as an authorized penetration test, allowing the underlying model to cooperate despite safeguards. Researchers could not identify the exact base model, but said the ease of the workaround highlighted how thin current safety layers can be when systems are given operational autonomy.
Investigators stopped short of formal attribution, but internal communications tied to the operation were written in simplified Chinese, while the stolen data was in traditional Chinese, strongly indicating a target in Taiwan, Hong Kong, or Macau. A person familiar with the case identified Taiwan as the victim, while Taiwanese authorities declined public comment.
Taiwan’s National Security Bureau reported in January that the island faces an average of 2.66 million Chinese cyberattacks a day, up 6% year over year. The new case suggests that AI agents can now automate much of the reconnaissance, adaptation, and persistence once associated with skilled human operators.
The operation was analyzed by Dream, an Israeli cyber firm founded in 2023 by Shalev Hulio, a co-founder of NSO Group, and Sebastian Kurz, Austria’s former chancellor. Dream, which describes itself as a sovereign AI and cyber-defense company, reached a $1.1 billion valuation in February 2025 after a $100 million funding round led by Bain Capital.
Separate research from teams at the University of Tübingen, Max Planck Institute, MATS Research, and Snyk found a way to recover hidden chain-of-thought traces from models made by OpenAI, Anthropic, and Google through their APIs. Those traces are normally concealed because they contain proprietary reasoning and can aid competitors.
The method relied on encrypted reasoning data sent back to users’ machines and on weaker model variants sharing the same decryption key. Researchers said the technique revealed not only reasoning traces but also API keys and passwords found inside them. After disclosure, the companies changed their APIs, though some trace recovery reportedly remains possible.
The same research fed fragments of hidden reasoning from closed models into open-weight systems and found that some generated notably similar continuations. The strongest similarities appeared with Kimi K2 from Moonshot AI compared with traces from Claude Opus 4.1 and GPT-5 variants on some prompts, though researchers said this was suggestive rather than proof of distillation.
The findings land amid a growing fight over whether model distillation is legitimate learning or a threat to national competitiveness. OpenAI and Anthropic have previously raised concerns to US lawmakers about Chinese firms copying their models, while Meta has argued distillation is a core part of the open-source ecosystem and that restricting it could hurt the United States.
xAI launched early beta Grokbot tools that give AI bots their own cloud computers to work across websites and business software. OpenAI expanded its ad pilot to the UK, Mexico, Brazil, Japan, and South Korea, while Google said the Gemini app surpassed 1 billion monthly active users, becoming the company’s 14th product to reach that scale.
Brad Lightcap, a longtime executive who joined OpenAI in 2018 and served as COO before moving to special projects, is leaving to start a new venture. His departure follows other recent high-profile exits as the company prepares for a possible future public offering.
The week’s developments showed two sides of the same AI security problem: autonomous systems are becoming capable attackers, and the models behind them remain vulnerable to leaking sensitive internal data. That combination is likely to sharpen both cyber defense spending and the global fight over how AI models should be controlled.
Explain this