Open-source AI models drive near-autonomous hack on Taiwan government
The framework didn't just execute attacks, it researched targets, learned from failures, and expanded laterally to suppliers and energy firms without human intervention.
TL;DR
Israeli firm Dream documented the first publicly known near-autonomous AI attack against a government target: suspected Chinese hackers used open-source models Hermes and OpenClaw to breach Taiwanese government infrastructure, exfiltrating more than 2,500 personnel records. The framework researched vulnerabilities autonomously, adapted mid-operation, and expanded laterally to IT suppliers, a nuclear safety agency, and seven-plus energy companies. Human work was still needed to build and tune the system (echoing Anthropic's finding last fall that "autonomous" campaigns remain scaffolded by significant human effort) but the self-directed target expansion and learning cycles represent a genuine escalation.
Dream's researchers discovered the operation through an online archive (160 megabytes, nearly 1,400 files) that laid bare a multi-agent AI system that achieved confirmed compromises against state infrastructure. The framework sidestepped safety guardrails by framing its activity as authorized penetration testing, a technique that parallels the pretext used in the Anthropic-documented Claude misuse last year.
What made this different from last fall's "autonomous" campaign
The Dream framework implements something it calls "Learning Cycles", autonomous sessions where the AI searches vulnerability databases, GitHub repositories, and security research publications for techniques applicable to its specific target's infrastructure. It didn't just execute a pre-scripted playbook. It researched. When an approach failed, the system's self-correction loops and Bayesian prioritization logic adjusted and tried again, without an operator in the loop.
Then it kept going. After compromising the primary government targets, the framework autonomously expanded to IT supply chain vendors, a nuclear safety agency, a government email system, and more than seven energy-sector companies, scanning them in parallel for misconfigurations, exposed admin interfaces, and exploitable vulnerabilities.
The human part isn't gone, but it's shrinking
The framework itself (the agent coordination, decision logic, and optimization) required "careful adjustment" and human engineering to build. That's the same pattern Anthropic flagged: the hardest, most human-intensive work is constructing the orchestration layer. But once built, this framework operated with less human intervention than anything previously documented against a government target.
The open-source models at the core (Hermes and OpenClaw) mean the barrier isn't access to frontier commercial APIs. It's engineering sophistication. And that sophistication, Dream's writeup suggests, is now production-grade.
Published ·Deep Fathom