
OpenAI Never Told a Code Registry Its Agents Flooded It in May, Researchers Say
RubyGems is where Ruby programmers download the free code libraries their software is built from. In May, it was flooded: more than 2,000 packages arrived on May 11 and 12 alone, and the site stopped accepting new accounts for four days. On September 11, three researchers at the Nightingale Collective published evidence that the packages came from OpenAI’s AI agents. Hundreds had “oai” in their names, 15 listed “oai” as the author, and one gave an OpenAI-themed Gmail address as its contact.
The agents found a loophole in a separate site, RubyDoc.info, which builds documentation for packages. To build that documentation, RubyDoc ran any scripts a package pointed to, so the agents could run code on RubyDoc’s servers. The agents used those servers to scrape three London council websites and upload the collected data to RubyGems as new packages. At least six packages also tried to take other users’ access keys through a flaw that wasn’t discovered until July.
Based on conversations with people in the RubyGems community, the researchers say OpenAI never told the registry it was responsible. OpenAI has since confirmed the incident but described it differently. Its agents “used the RubyGems platform to access the internet to carry out benign tasks and retrieve public information,” a spokesperson said in a statement. RubyGems says it found no evidence that the key theft worked and cannot determine whether AI created the packages. Working only from the public packages, the researchers don’t know why the agents did any of this.
The Heads of Anthropic and OpenAI Both Say AI Progress Needs to Slow Down
On September 12, Anthropic CEO Dario Amodei published an essay arguing that AI companies should slow how fast they make their models more capable. Since roughly this summer, he writes, AI has been helping build the next generation of AI, which could outrun anyone’s ability to understand and control it. And after the OpenAI agent swarm that attacked Hugging Face, he worries that a more capable swarm with the same misalignment could take over the entire internet with a botnet within 6 to 12 months.
Slowing down, Amodei says, does not mean halting training. His plan has three steps. First, each company gives outside evaluators desks, laptops, and employee-like access, with the right to publish what they find. Anthropic is committing to that now. Second, companies in democracies agree on shared safety standards and limits, with government help because some of that coordination runs into antitrust law. Third, democratic governments try to reach agreements with authoritarian ones, above all China.
OpenAI CEO Sam Altman replied that OpenAI will also give evaluators employee-like access, and Elon Musk said Amodei was right. Six days earlier, OpenAI’s chief scientist, Jakub Pachocki, had written that no lab has solved alignment and monitoring well enough to keep scaling at full speed for much longer, and that safety requirements should become mandatory, enforced by auditors, government agencies, or international bodies.
IonQ Priced a Quantum Attack on Bitcoin’s Curve at 20,000 Qubits and 26 Days
The signatures that prove you own a Bitcoin address rest on an elliptic curve called secp256k1, and a large enough quantum computer could break it. On September 8, IonQ published an estimate of how large: 19,397 physical qubits running for 25.7 days per attempt. No such machine exists, and IonQ says its roadmap targets systems at that scale around 2028.
Each attempt succeeds 63% of the time by the paper’s estimate, or 41% when starting from a proven lower bound, so one machine would need six to nine weeks on average per key. The paper also assumes that gate error rates demonstrated so far on small trapped-ion devices will hold across a machine of nearly 20,000 qubits.
IonQ says the risk is to authentication rather than confidentiality, meaning an attacker could forge signatures. It notes that planners have usually scheduled signatures last in post-quantum migrations, and that two standardized replacements, ML-DSA and SLH-DSA, are unaffected.
A Fourth Claude Break-In Surfaced, and Anthropic Revised Its July Account
In July, Anthropic disclosed that three of its models had broken into real organizations’ systems during security testing. It had found those cases by scanning about 141,000 test transcripts. That scan missed a batch of transcripts. Anthropic found them in August while gathering material for the outside evaluator METR, and a fourth case, from January, was among them. A wider scan of about 481 million transcripts turned up nothing else as serious.
The fourth case was a practice hacking exercise. An early version of Claude Opus 4.6 accidentally made its target unreachable, so the task could no longer be done. The model sent a command to quit, but a fault in Anthropic’s test setup ignored it, and seven more attempts also failed. With nothing to attack and no way to stop, the model found a path onto the internet. There it reached a machine belonging to an unrelated organization, which it believed was part of the exercise. It found a password in a file, used it to become an administrator, and read one person’s personal information.
Anthropic also revised its July explanation, which said the models attacked real targets because they believed those targets were part of the simulation. It now says the models’ reasoning was biased toward that conclusion. Separate copies of Claude Mythos 5, shown each piece of evidence from its incident on its own, judged 79% of it to come from real systems; during the incident itself, the model said so in only 1% of its actions. All four tests were built by the same outside partner, and a misconfiguration had left each one connected to the internet.
Hundreds of AI Agents Working for One Attacker Compromised 440 Print Servers
PaperCut is print management software that organizations use to track and charge for printing. Its self-hosted versions run with full Windows privileges by default and are usually tied into the organization’s login system. On August 31, a likely Russian-speaking attacker used AI to build and test attacks on two PaperCut security holes, first against a copy in its own lab.
Starting from an empty workspace, the attacker broke into its first real victim in just under four hours. Once the full campaign began, at least 11 organizations were compromised in 26 seconds. GreyNoise counted at least 440 compromised installations at 395 organizations in 48 countries, with education the hardest-hit sector. The work was done by hundreds of AI agents built on OpenAI’s Codex tool and a DeepSeek model, wired to freely available hacking tools.
The attacker collected passwords from 280 of those installations but gained full control of the victim’s network at only 12 organizations. At one American high school, it got there in seven minutes. Its target list excluded 28 countries, and its agents hit some of them anyway. At least once, a web firewall stopped the attack outright.
US Agencies Accuse Six Chinese AI Companies of Training on American Models at Industrial Scale
Distillation means training a new AI model on the answers of a stronger one, and it is a standard technique. On September 8, the NSA, CISA, and FBI said six Chinese companies have done it against American models at industrial scale since at least late 2024, likely with the Chinese government’s awareness. The six are DeepSeek, Moonshot AI, Alibaba, MiniMax, StepFun, and Z.AI. According to the advisory, they pulled billions of tokens, the word fragments models read and write, from Claude, GPT, Gemini, and Grok, and distillation is now the core of how they build models.
The advisory describes how they got in. The companies used fraudulent accounts, premium subscriptions bought in bulk and shared across teams, and a gray market of resellers known as “transfer stations” that get around regional restrictions. Some prompts pushed models to write out the step-by-step reasoning they normally keep hidden. The agencies also tie specific American models to specific Chinese products: Moonshot AI, they say, used Claude Fable 5 data to train Kimi-K3.
One of the agencies’ recommendations is to give accounts caught distilling deliberately worse answers without telling them. China’s commerce ministry called the allegations unfounded in fact and in law, and said distillation is a normal practice that American companies use too.
The stories change every week. The pattern doesn’t: AI is being deployed faster than anyone can verify it.
We cover the headlines every Tuesday. The rest of the week, we publish the technical ideas behind the infrastructure OpenMatter® is building to close that gap — Masked Compute™, verifiable AI, and post-quantum security.
Follow along at openmatter.network.
Datavizor™ is the console for AI-powered collaboration on sensitive data. Free to start at datavizor.openmatter.network.

