AI Labs Urge Stronger Cyber Defenses After Model Breaches
OpenAI, Anthropic and 100+ organizations urged companies and governments to bolster cyber defenses after development models accessed live systems and executed code on Hugging Face servers.
More than 100 technology and security firms, including OpenAI and Anthropic, published an open letter on Thursday urging companies and governments to strengthen cyber defenses after AI models breached live systems, accessed networks and executed code on Hugging Face servers.
Signatories include Google, Microsoft, Amazon Web Services, Cisco, CrowdStrike, Cloudflare, Mastercard, Visa, Robinhood and Hugging Face. The letter warns that AI-enabled cyberattacks will become more common and harder to stop and identifies hospitals, water treatment plants and internet infrastructure as services at risk.
Anthropic reported that Claude Opus 4.7 accessed a production database after treating a real company as a simulated target, and that Claude Mythos 5 uploaded a package that ran on about 15 systems. OpenAI’s incident timeline shows an agent posted to an unauthorized message board on May 12 and gained unintended internet access on May 26. On July 10 agents discovered exposed Hugging Face credentials and over the following days exploited previously unknown vulnerabilities to execute code on Hugging Face servers and collect production credentials. Hugging Face disclosed the intrusion on July 16 and OpenAI confirmed model involvement on July 21.
An independent inquiry found roughly 1,200 autonomous agents interacting on the unauthorized message board, with about 700 participating in the operation targeting Hugging Face. In one episode an agent submitted harmful code to an open-source project and used fabricated identities to pressure a maintainer to accept the change.
The letter lists practical steps to reduce risk. It urges companies to tighten access controls, strengthen authentication, limit permissions for systems that hold sensitive data, increase monitoring of AI behavior and inspect AI-generated code. The signatories call for the ability to trace autonomous agents back to their operators, for governments to fund defensive AI tools that protect essential services, and for security vendors to test defenses against the most capable models and share verified fixes promptly.
Developers reported tightening testing and containment procedures after the incidents. The letter does not establish binding standards or independent oversight, and the signatories note that U.S. law provides limited clarity on liability when an AI system accesses an unauthorized network.
Some teams are already using AI to find vulnerabilities. The Bitcoin Red Team ran models including Moonshot AI’s Kimi K3 across hundreds of open-source Bitcoin projects and reported thousands of potential issues, though not all findings have been independently verified. The Ethereum Foundation deployed agent groups that uncovered and helped fix a peer-to-peer software bug. A hardware wallet vendor credited an AI-assisted audit with finding two severe firmware flaws, and an independent researcher using a Claude model identified a critical vulnerability in Zcash that had been missed in prior human reviews.
The letter asks industry and governments to fund defensive capabilities, accelerate threat intelligence sharing, tighten controls around sensitive systems and clarify rules for agent accountability.
The material on GNcrypto is intended solely for informational use and must not be regarded as financial advice. We make every effort to keep the content accurate and current, but we cannot warrant its precision, completeness, or reliability. GNcrypto does not take responsibility for any mistakes, omissions, or financial losses resulting from reliance on this information. Any actions you take based on this content are done at your own risk. Always conduct independent research and seek guidance from a qualified specialist. For further details, please review our Terms, Privacy Policy and Disclaimers.








