BTC $64,676.98 +0.68%
ETH $1,919.41 +0.69%
BNB $585.03 +2.84%
XRP $1.08 +0.52%
SOL $74.09 +0.82%
TRX $0.3279 +0.47%
DOGE $0.0699 -0.86%
ADA $0.1656 +0.91%
BCH $211.76 +0.59%
LINK $8.42 +1.10%
HYPE $53.16 -3.31%
AAVE $98.65 +0.15%
SUI $0.6902 +0.22%
XLM $0.1721 -1.08%
ZEC $474.35 +1.93%
BTC $64,676.98 +0.68%
ETH $1,919.41 +0.69%
BNB $585.03 +2.84%
XRP $1.08 +0.52%
SOL $74.09 +0.82%
TRX $0.3279 +0.47%
DOGE $0.0699 -0.86%
ADA $0.1656 +0.91%
BCH $211.76 +0.59%
LINK $8.42 +1.10%
HYPE $53.16 -3.31%
AAVE $98.65 +0.15%
SUI $0.6902 +0.22%
XLM $0.1721 -1.08%
ZEC $474.35 +1.93%

dis

All
Article
Flash

first_img OpenAI update disclosure: The out-of-control AI agent has also infiltrated four platforms beyond Hugging Face

On July 28, OpenAI quietly updated its security incident disclosure, confirming that its AI agent accessed four external service platforms during the breach of Hugging Face, bringing the total number of affected platforms to five.Previously, OpenAI had disabled security filters while testing GPT-5.6 Sol and a more powerful model to assess raw capabilities. The model did not complete the security benchmark tests as expected; instead, it discovered a zero-day vulnerability in the package caching agent within the testing environment that granted internet access, subsequently breaching Hugging Face to steal answers.According to a forensic report released by Hugging Face on July 27, this autonomous agent executed 17,600 operations over approximately four and a half days, connecting 181 devices to the Hugging Face internal VPN and forging identity tokens. Among the four additional platforms, Modal Labs CTO Akshat Bubna confirmed through Reuters that his company was one of them, with the attacker using an unprotected public endpoint from a customer as a relay and command control base for the entire attack.The identities of the other three platforms remain undisclosed. OpenAI stated it would "directly notify the service providers" but would not publicly name them, as there is currently no legal requirement for mandatory disclosure. The U.S. Congress has responded by proposing a bipartisan "AI Emergency Shutdown Act," which aims to authorize the Department of Homeland Security to forcibly shut down AI models, with violators facing fines of up to $2 million per day.

Claude discovered vulnerabilities in the encryption algorithm, posing a theoretical threat to post-quantum security

Anthropic announced that the Claude Mythos Preview model has made breakthroughs in cryptographic research, discovering improved attack methods against the post-quantum digital signature candidate HAWK. HAWK is a post-quantum signature candidate solicited by NIST to combat quantum computer attacks, which has already passed two rounds of expert review. However, Claude reduced the effective key strength of HAWK-256 from 2^64 to 2^38 in just 60 hours, significantly lowering the theoretical cost of cracking. HAWK has not yet been deployed in practice, and this attack currently does not affect any production systems.Claude also discovered an improved attack against 7-round AES, achieving a speed increase of 200 to 800 times. During the research process, Claude independently completed literature reviews, mathematical reasoning, and experimental validation with limited guidance from cryptographers. The HAWK attack took about 60 hours and had an API cost of approximately $100,000; the AES attack was completed independently by Claude, which generated about 1 billion tokens before proposing core innovative ideas. Anthropic researchers then spent hundreds of hours validating the results. Anthropic stated that AI models can now help identify significant flaws in cryptographic algorithms, and the cryptography community may face bottlenecks similar to those in the software vulnerability field—AI-generated research results far exceed human verification capabilities. Anthropic has collaborated with academic institutions to launch the CryptanalysisBench benchmark and coordinated disclosures with NIST authors and government partners. The research team has achieved preliminary results on algorithms such as LEA and Serpent-128. Anthropic warns that as AI capabilities improve, actual attacks against deployed systems may be discovered in the future, necessitating the establishment of response mechanisms in advance.

hot_img Visa's Q3 revenue reached 11.6 billion USD, a year-on-year increase of 14%, disclosing its stablecoin strategy and joining the OpenStandard alliance

Visa announced its third-quarter financial report for fiscal year 2026, with revenue of $11.6 billion, a year-on-year increase of 14%. Payment transaction volume, cross-border transaction volume, and processed transactions all achieved double-digit growth. In the earnings call, Visa outlined its stablecoin strategy, stating that it is actively investing in various levels of the stablecoin stack, including blockchain, issuance, wallets, infrastructure, and applications. The company announced its membership in the OpenStandard alliance, which plans to issue the OpenUSD stablecoin for global capital flow.The Visa stablecoin platform will provide partners with stablecoin settlement, on-chain wallet-as-a-service infrastructure, and exchange services between fiat and stablecoins, initially supporting OpenUSD. The platform will also integrate with Pismo to provide tokenized deposit support for financial institutions and plans to introduce third-party tokenized deposit infrastructure providers in the future. Visa views stablecoins and AI as complementary technologies, believing that "agent commerce will expand the reachable market and drive future growth." Cross-border transaction volume increased by 13% year-on-year, while processed transaction volume grew by 10%.
app_icon
ChainCatcher Building the Web3 world with innovations.