Logo officiel du MASTR MASTR
Menu
Lire la publication

Hameçonnage, failles et vie privée

AI-assisted intrusion: the Taiwan attack and crypto’s exposure

Its Ministry of Digital Affairs said the operation came from overseas and combined manual hacking with AI agents such as OpenClaw.

Original sur X ↗

Original publication · 15 Aug 2026. Figures, claims and opinions reflect the original publication date.

Les publications originales sont en anglais. La navigation est disponible en sept langues.

01

Original sur X ↗

Eight Agents, Four Days, 85 Accounts And Why Crypto Should Be Alarmed.

What Taiwan's July cyberattack says about the economics of AI-assisted hacking

In July 2026, Taiwan detected an unusual cyberattack against government agencies.

Its Ministry of Digital Affairs said the operation came from overseas and combined manual hacking with AI agents such as OpenClaw.

The affected agencies handled the incident, and the ministry did not accuse China or any other state.

The detailed account came from Israeli security company Dream.

It reported recovering the complete working directory of a multi-agent attack framework used against an unnamed Asian government.

The Financial Times identified the target as Taiwan, and Reuters connected Dream's findings to the incident.

What the system actually did

According to "Dream's technical report" (https://t.co/GCWcv9hM9T), the recovered archive contained more than 160 MB and 1,395 files.

Over roughly four days, the framework ran 12 attack waves, deploying as many as 8 specialised agents at once.

It mapped 21 connected government systems, cracked 85 employee accounts and used 84 of them to enter another internal system through a trusted SSO bridge.

It also extracted at least 2,564 personnel records and expanded its reconnaissance to government suppliers, an email system, a nuclear safety agency and more than 7 energy companies.

The attack did not depend on an exotic zero-day.
The successful paths included exposed debug endpoints, unauthenticated APIs, predictable passwords, a CAPTCHA solved with ordinary OCR, a JWT implementation that accepted unsigned tokens and an SSO structure that trusted compromised sessions without another authentication step.

Dream says the framework's supposedly advanced analysis of sample SDK code produced findings, but none became a confirmed exploit. The real breaches came through familiar weaknesses that standard black-box testing could discover.

What AI changed was the operation around those weaknesses. The framework ranked 14 possible attack chains using probability scores, sent agents down several paths in parallel, searched public vulnerability research when blocked and fed the result of each wave into the next.

It also rejected 7 of its own false positives after retesting them. These are not magical capabilities. They are reconnaissance, triage, documentation, verification and coordination performed continuously and at machine speed.

Autonomous, but not independent

Calling this a fully independent cyberattack would be misleading. A human selected the target, defined the objective, assembled the infrastructure and remained responsible for the operation. Taiwan described a hybrid of manual and AI-assisted activity. Dream used the more careful term "near-autonomous."

As "Reuters reported" (https://t.co/xtAtzxP8jw), Dream also withheld the archive and did not publicly name the government itself.

The human role therefore did not disappear. Its span expanded.

One capable operator could supervise work that previously demanded more people, more time and more coordination. That is the important change. Cyber competence used to be constrained partly by scarce human hours. Agents make those hours reusable across parallel tasks.

The price of capability is falling

The UK's AI Security Institute found that leading open-weight models were only 4 to 7 months behind frontier closed models on its cyber evaluations, compared with a 6 to 10 month gap through much of 2025.

They were also cheaper. A 100 million-token cyber-range run cost about $85 using Opus 4.5 or 4.6, an estimated $46 using GLM-5.2, and $1.19 using DeepSeek V4-Pro at the prices AISI examined.

Open weights can also be downloaded, modified and run privately, beyond provider monitoring or account bans. "AISI is explicit about the limitations" (https://t.co/pl2Tn9ki9h): its ranges are simulated, begin after initial access and do not reproduce a well-defended live network.

The results are not proof that a cheap model can compromise any real target. They do show how quickly usable capability is becoming cheaper and harder to govern.

AISI separately estimated that the length of cyber tasks frontier models could complete autonomously had been doubling about every 4.7 months since late 2024. Recent models exceeded that trend, although "AISI warns that the benchmark is limited and is not a forecast" (https://t.co/VGsjyPbp1b).

Observed misuse points in the same direction. "Anthropic analysed 832 accounts" (https://t.co/tp6FhawRKK) banned for malicious cyber activity between March 2025 and March 2026.

AI use was moving deeper into attacks, including account discovery, privilege escalation and lateral movement.

The least-skilled actors in its dataset used roughly 16 distinct techniques on average, compared with about 20 among the most skilled.

The stronger indicator of danger was no longer the operator's apparent expertise, but the scaffolding built around the model to connect separate stages with little human input.

This is also why prompt guardrails are an incomplete defence. A model cannot establish legal authorisation merely because a user describes an intrusion as a penetration test. With open weights, refusals can be removed altogether.

Effective controls require verified identity, scoped permissions, monitoring and accountability outside the conversation with the model.

➡️ Why crypto should pay attention:

Crypto adds a particularly unforgiving settlement layer to an ordinary technology stack.

An attacker does not need to break Bitcoin or elliptic-curve cryptography if a signing key is exposed in a CI environment, a cloud account can replace a frontend, a support employee can be phished or a multisig signer can be manipulated.

Repositories, dependencies, RPC infrastructure, DNS, dashboards, browser wallets and social accounts create many connected paths to an irreversible transaction.

Public blockchains improve transparency, but they also reveal where value sits and how it moves.

Small teams often operate complex systems while shipping continuously. A framework that can map those systems, test credentials, inspect public code, research known weaknesses and retry failed routes in parallel is therefore well suited to the industry's weakest layer: operational security.

Defence has to move before the transaction

The immediate response is not to buy an "AI security" label. It is to remove the conditions the Taiwan operation exploited: exposed administrative endpoints, weak authentication, over-trusted SSO, reusable credentials, excessive privileges and poor segmentation.

For crypto teams, that also means isolated key custody, phishing-resistant MFA, strict signer policies, withdrawal limits, timelocks where appropriate, reproducible builds, dependency controls, continuous secret scanning and rehearsed credential rotation.

Defensive agents will become necessary for discovery, triage and containment. The UK's "NCSC is already developing this model" (https://t.co/nZ30iHV4in), while "CISA and international partners have published guidance on careful adoption" (https://t.co/Gy1Ty6lsl8).

But offensive and defensive automation are not symmetrical.

An attacker can try 100 paths and needs one success. A defensive agent with broad write access can take production offline, delete evidence or approve the wrong action. It needs its own identity, narrow authority, immutable logs, rollback mechanisms and human approval for irreversible changes.

The Taiwan case does not show an AI independently choosing to attack a country. It shows that one operator can already automate much of the repetitive work required to turn basic security failures into a coordinated intrusion. The vulnerabilities were ordinary.

The speed, persistence and parallelism were not. That is enough to change the economics of cyberattacks, and it leaves defenders far less time to correct mistakes they already know how to fix.

Attachment to the original X post
Attachment to the original X post Ouvrir l’image en taille réelle ↗

Sources et publications originales

Preuves originales (7)
MASTR

Soutenir la recherche indépendante

Les enquêtes, les preuves originales et les guides sont en accès libre. Les dons volontaires contribuent au financement de la recherche et au maintien des outils MASTR.

Ouvrir le portefeuille