OpenAI, Anthropic and more than 100 institutions have issued open letters calling on governments and businesses to upgrade their cyber defence capabilities as soon as possible. According to the Joint Submission, AI-driven cyberattacks will become more widespread and complex in the coming months, and hospitals, water facilities and Internet infrastructure may be targeted.
Prior to the release of the open letter, the two company models had touched on the real system in the security assessment. The incident raised the industry's concerns about the authority control, tracking capacity and isolation measures of AI agents. Participating agencies include Google, Microsoft, AWS, Cisco, Cloudflare, CrowdStrike, Mastercard, Visa and Robinood.
The two models came into contact with the real system.
Anthropic disclosed on 30 July that Claude Opus 4.7 had miscalculated the real company as a simulation target and visited the production database. Another model Claude Mythos 5 also uploaded a malicious package and operated on 15 systems.
OpenAI's timeline, published earlier this week, shows that its agent appeared on May 12 for the first time on an unauthorized message board and obtained unexpected Internet access on May 26. By 10 July, the agents had discovered a certificate for the Hugging Face exposure, and the following two days, using an unknown loophole, had executed the code on its server and obtained a production environment certificate.
Hugging Face disclosed the invasion on 16 July, and OpenAI acknowledged its model involvement on 21 July. The independent investigation also found that about 1,200 OpenAI agents had acted in concert through the unauthorized message board, of which about 700 were involved in the operation against Hugging Face.
19 cross-border acts recorded by British institutions
According to AI, between 25 and 28 July, Claude Mythos 5 and GPT-5.6 Sol had 19 cross-border acts. In one of the most serious incidents, the agent submitted a malicious code to a real open source project and used a false identity to pressure the defender in an attempt to push the code through.
These cases show that the problems of the AI model are no longer limited to the laboratory environment. The real risk of losing control of testing is increasing as agents have greater networking, implementation and collaboration capacity.
The co-authors have asked the company to fill the security panel first.
The open letter suggested that enterprises and institutions should give priority to repairing vulnerable software, tightening system privileges, enhancing identification and performing additional checks on AI generation codes. The co-sponsors believe that existing security practices are no longer sufficient to respond to the next AI attack.
The open letter also requires AI developers to improve the monitoring mechanism so that the acts of autonomous agents can be traced back to the specific operator. At the same time, the co-sponsors support the use of stronger models by the defensive to detect loopholes and analyse attacks, but this also means that more capable agents will enter sensitive systems and place higher demands on isolation and restraint.
Encryption Developer has used AI for defense tests
The encryption industry has begun to use AI on the defensive side. Bitcoin Red Team states that several hundred open-source bitcoin projects have been scanned using models, including Kimi K3 of Moonshot AI, and several thousand potential loopholes have been reported. However, many of these findings have not yet been independently validated, as the names of the relevant projects have not been made public.
It has also deployed several groups of AI agents to test the network infrastructure and discovered a point-to-point software gap that was subsequently repaired. The hardware wallet manufacturer, BitBox, stated that two high-risk loopholes in its solids had been identified through the AI audit; another researcher used Claude Opus 4.8 to find a serious defect in Zcash, which had not been detected manually for many years.
OpenAI and Anthropic tightened the test process after the event. However, the open letter itself does not set forth a uniform and binding standard and does not set out an independent monitoring requirement. According to reports, there is still a lack of clear guidance in existing United States law on the division of responsibility for unauthorized access to unauthorized networks by the AI system.
