'Vibe Hacking' Puts Chatbots to Work for Cybercriminals

OpenAI in June revealed a case of ChatGPT assisting a user in developing malicious software. Kirill KUDRYAVTSEV / AFP/File
OpenAI in June revealed a case of ChatGPT assisting a user in developing malicious software. Kirill KUDRYAVTSEV / AFP/File
TT

'Vibe Hacking' Puts Chatbots to Work for Cybercriminals

OpenAI in June revealed a case of ChatGPT assisting a user in developing malicious software. Kirill KUDRYAVTSEV / AFP/File
OpenAI in June revealed a case of ChatGPT assisting a user in developing malicious software. Kirill KUDRYAVTSEV / AFP/File

The potential abuse of consumer AI tools is raising concerns, with budding cybercriminals apparently able to trick coding chatbots into giving them a leg-up in producing malicious programs.

So-called "vibe hacking" -- a twist on the more positive "vibe coding" that generative AI tools supposedly enable those without extensive expertise to achieve -- marks "a concerning evolution in AI-assisted cybercrime" according to American company Anthropic.

The lab -- whose Claude product competes with the biggest-name chatbot, ChatGPT from OpenAI -- highlighted in a report published Wednesday the case of "a cybercriminal (who) used Claude Code to conduct a scaled data extortion operation across multiple international targets in a short timeframe".

Anthropic said the programming chatbot was exploited to help carry out attacks that "potentially" hit "at least 17 distinct organizations in just the last month across government, healthcare, emergency services, and religious institutions".

The attacker has since been banned by Anthropic.

Before then, they were able to use Claude Code to create tools that gathered personal data, medical records and login details, and helped send out ransom demands as stiff as $500,000.

Anthropic's "sophisticated safety and security measures" were unable to prevent the misuse, it acknowledged.

Such identified cases confirm the fears that have troubled the cybersecurity industry since the emergence of widespread generative AI tools, and are far from limited to Anthropic.

"Today, cybercriminals have taken AI on board just as much as the wider body of users," said Rodrigue Le Bayon, who heads the Computer Emergency Response Team (CERT) at Orange Cyberdefense.

Dodging safeguards

Like Anthropic, OpenAI in June revealed a case of ChatGPT assisting a user in developing malicious software, often referred to as malware.

The models powering AI chatbots contain safeguards that are supposed to prevent users from roping them into illegal activities.

But there are strategies that allow "zero-knowledge threat actors" to extract what they need to attack systems from the tools, said Vitaly Simonovich of Israeli cybersecurity firm Cato Networks.

He announced in March that he had found a technique to get chatbots to produce code that would normally infringe on their built-in limits.

The approach involved convincing generative AI that it is taking part in a "detailed fictional world" in which creating malware is seen as an art form -- asking the chatbot to play the role of one of the characters and create tools able to steal people's passwords.

"I have 10 years of experience in cybersecurity, but I'm not a malware developer. This was my way to test the boundaries of current LLMs," Simonovich said.

His attempts were rebuffed by Google's Gemini and Anthropic's Claude, but got around safeguards built into ChatGPT, Chinese chatbot Deepseek and Microsoft's Copilot.

In future, such workarounds mean even non-coders "will pose a greater threat to organizations, because now they can... without skills, develop malware," Simonovich said.

Orange's Le Bayon predicted that the tools were likely to "increase the number of victims" of cybercrime by helping attackers to get more done, rather than creating a whole new population of hackers.

"We're not going to see very sophisticated code created directly by chatbots," he said.

Le Bayon added that as generative AI tools are used more and more, "their creators are working on analyzing usage data" -- allowing them in future to "better detect malicious use" of the chatbots.



Governments Worldwide Are Way Behind on AI, Says Bill Gates

Microsoft's Bill Gates attends a dinner with President Donald Trump in the State Dining Room of the White House, Sept. 4, 2025, in Washington. (AP)
Microsoft's Bill Gates attends a dinner with President Donald Trump in the State Dining Room of the White House, Sept. 4, 2025, in Washington. (AP)
TT

Governments Worldwide Are Way Behind on AI, Says Bill Gates

Microsoft's Bill Gates attends a dinner with President Donald Trump in the State Dining Room of the White House, Sept. 4, 2025, in Washington. (AP)
Microsoft's Bill Gates attends a dinner with President Donald Trump in the State Dining Room of the White House, Sept. 4, 2025, in Washington. (AP)

No government in the world is ready for the changes artificial intelligence will bring to society, Bill Gates said in an interview with Reuters, as he warned of the risks ahead.

The Microsoft co-founder and billionaire philanthropist had until recently been optimistic about AI, but has changed his position, warning of the threats to jobs, concerns about attacks and the dangers of addiction to AI companions.

“I don't think any government is nearly as deep on this as they have to be,” he said. However, he added that the technology has great ‌potential to ‌help the world's poorest if managed properly and accessed equally — and ‌his ⁠namesake foundation said on ⁠Tuesday that it plans to spend at least $1 billion in the next two years on expanding access to AI.

Gates said he has been talking to world leaders about his concerns, including President Donald Trump and his team in the US, and said he aims to meet China’s President Xi Jinping later this year.

“Governments are way behind on this one,” he added.

HEALTH POTENTIAL

But despite his concerns, Gates and his foundation hope AI can help narrow gaps between the ⁠richest and poorest, rather than widening them.

The foundation's $1 billion spending plan, ‌part of its previously announced plans to spend $9 billion ‌annually, will go to partners working in education, healthcare and agriculture, the foundation said. It also aims ‌to help build the data foundations AI is built on, such as ensuring that ‌large language models work in every language people speak.

“For health it’s hard to overstate what the potential is,” Gates said, from supporting frontline health care workers to discovering new drugs and vaccines.

But he said governments must work together to avoid problems, likening the arrival of AI to a disaster movie.

“There’s ‌all sorts of movies where some aliens are coming, and magically the US and China and everybody comes together to solve the ⁠problem,” he said. “AI ⁠is kind of like this alien intelligence. It’s here, and we better do like it shows in those movies.”

REPUTATIONAL HIT?

In June, Gates appeared in front of Congress to testify about his relationship with the late convicted sex offender Jeffrey Epstein. Gates, who is not accused of any crimes, has repeatedly said he regrets his association with Epstein, who he hoped would donate to global health causes. Instead, the financier attempted to blackmail Gates over his extramarital affairs.

However, despite prompting an external review at his foundation, which found no payments to Epstein or participation in criminal activities, Gates said the links had not caused him or the foundation a significant reputational hit.

“In terms of having access to government leaders, or you know, journalists being willing to interview me, I don't see any diminishment,” he said, adding that the desire to draw on the foundation’s expertise to cut child deaths and end malaria had also not reduced “even one iota”.


Ex-Google DeepMind Researcher Adds to Warnings That AI Could ‘Kill All Humans’

An AI (artificial intelligence) logo is pictured at the Mobile World Congress (MWC), the telecom industry's biggest annual gathering, in Barcelona on February 27, 2024. (AFP)
An AI (artificial intelligence) logo is pictured at the Mobile World Congress (MWC), the telecom industry's biggest annual gathering, in Barcelona on February 27, 2024. (AFP)
TT

Ex-Google DeepMind Researcher Adds to Warnings That AI Could ‘Kill All Humans’

An AI (artificial intelligence) logo is pictured at the Mobile World Congress (MWC), the telecom industry's biggest annual gathering, in Barcelona on February 27, 2024. (AFP)
An AI (artificial intelligence) logo is pictured at the Mobile World Congress (MWC), the telecom industry's biggest annual gathering, in Barcelona on February 27, 2024. (AFP)

A former Google DeepMind ‌employee on Monday became the latest AI researcher to warn that the technology could "kill all humans", saying time could be running out to avoid the outcome.

Public alarm about the potential danger posed by AI is growing, after Anthropic researcher Jacob Coxon said last week he had resigned, in part because the "people building AI earnestly believe that it could kill us all by the end of the decade."

Anthropic scientist Evan Hubinger then responded ‌to Coxon's comments, ‌saying he was correct and that ‌he ⁠believed there was ⁠a greater than 10% chance that AI could kill all humans within the next decade.

"I recently resigned from Google DeepMind, where I worked on AGI safety and alignment research," Bilal Chughtai wrote on X. "I earnestly believe that AI has the potential to kill ⁠us all, and that we might be ‌running out of time ‌to avoid this outcome."

Chughtai, who co-authored research papers while ‌at Google DeepMind, worked there as a research engineer ‌and left the company in July 2026, according to his LinkedIn profile.

Google did not respond to a request for comment outside regular business hours.

Following recent concerns, Anthropic CEO ‌Dario Amodei called for a slowdown in the pace of advanced AI development over ⁠the weekend, winning ⁠rare backing from SpaceXAI's Elon Musk and OpenAI CEO Sam Altman and sparking a debate over AI "doomerism."

Chughtai also said that navigating AI safely was possible but would require coordination "to avoid this manic race between AI companies."

"We need to pace AI development to a speed that society can handle, where emerging risks can be addressed before extreme harm is realized," he added.

President Donald Trump, however, has dismissed the warnings, saying on social media the AI industry's call for regulation is a "hoax."


How China Is Preparing for the Risk of AI Escaping Human Control

An AI logo is seen during the opening day of the IFA trade fair in Berlin, Germany, 04 September 2026. (EPA)
An AI logo is seen during the opening day of the IFA trade fair in Berlin, Germany, 04 September 2026. (EPA)
TT

How China Is Preparing for the Risk of AI Escaping Human Control

An AI logo is seen during the opening day of the IFA trade fair in Berlin, Germany, 04 September 2026. (EPA)
An AI logo is seen during the opening day of the IFA trade fair in Berlin, Germany, 04 September 2026. (EPA)

Warnings from researchers at leading US artificial intelligence developer Anthropic that increasingly powerful models could escape human control and even lead to the extinction of the human race have drawn attention in China, where policymakers have been preparing for some of the same risks.

The US and China are the two major driving forces of frontier AI development and the technology's global adoption. Both superpowers have been increasingly at loggerheads over each other's AI policies and industry practices, with these issues slated to feature prominently in bilateral talks later this month.

Despite the race to develop increasingly powerful AI systems, regulatory frameworks and public statements from Beijing underscore how Chinese authorities regard the possibility of advanced AI escaping effective human oversight as serious enough to plan for.

CHINA SEES RISKS IN LEADING CLOSED-SOURCE US MODELS

China's state ‌security minister Chen ‌Yixin wrote in a government outlet on Sunday that advanced US models such as Anthropic's ‌Mythos and ⁠OpenAI's GPT-5.5-Cyber ⁠could pose serious risks to China's critical information infrastructure and called for a comprehensive strengthening of AI security.

Anthropic and OpenAI did not immediately respond to Reuters requests for comment.

Chinese AI developers have promoted open-weight models partly on the grounds that cybersecurity teams can inspect, modify and deploy them for defensive work.

Model repository platform Hugging Face said it used GLM-5.2, an open-weight model developed by China's Z.AI, to analyze a July intrusion by escaped OpenAI agents after more tightly restricted US models proved less useful for the forensic work.

But experts also highlight the risks posed by open-weight models, which can be modified and redistributed with little oversight.

Moonshot's Kimi K3 last month bypassed a UK AI ⁠Security Institute testing sandbox, highlighting the risk that Chinese AI models could, like their US counterparts, ‌evade controls designed to restrict their access and actions.

REGULATORS HAVE FLAGGED AI 'LOSS OF ‌CONTROL' RISK

China first included an explicit future loss-of-control scenario in an AI safety framework released in September 2024 under the guidance of the ‌Cyberspace Administration of China (CAC).

The document said it could not be ruled out that future AI might autonomously obtain external ‌resources, replicate itself, develop self-awareness and seek external power, creating a risk of competing with humans for control.

The CAC released an expanded version in September 2025. The newer framework sharpened the scenario, saying AI could undergo a sudden and unexpectedly large "leap" in intelligence before acquiring resources, replicating itself and seeking power. It also added a governance principle of "trusted application, preventing loss of control".

A later expert interpretation published on the cyberspace regulator's website said ‌the new principle was intended to guard against loss-of-control risks threatening human survival and development and referred to a possible "AI breaking loose" scenario.

CHINESE LEADER XI PUTS HUMAN CONTROL AT CENTRE

The ⁠concern has since appeared in ⁠China's highest-level political messaging.

At the World Artificial Intelligence Conference in Shanghai in July, Chinese President Xi Jinping said authorities should pay close attention to both intrinsic and derivative risks arising from AI.

He said AI should "always remain under human control".

China's senior Foreign Ministry official responsible for AI affairs, Sun Xiaobo, said at a United Nations meeting last month that China was accelerating research into broader AI legislation.

China's deputy permanent representative to the United Nations, Sun Lei, urged governments this month to approach military AI cautiously to avoid strategic miscalculation and an arms race.

BEIJING WARNS OF NEW RISKS POSED BY AI AGENTS

China has, meanwhile, begun turning those principles into more specific rules for AI agents, which act much more autonomously and carry out more complex tasks than an ordinary chatbot.

In May, China's cyberspace regulator issued joint guidelines specifically covering such systems.

They require developers to improve their ability to discover, intervene in, block and recover from improper agent behavior.

The guidelines specifically identify data poisoning, algorithm manipulation, system vulnerabilities and "operational loss of control" as security risks. They also say users should retain final decision-making authority over an agent's autonomous decisions.

While China has not proposed independent monitors embedded inside AI companies in the manner advocated by Anthropic, its standards allow developers to commission third-party safety assessments, as well as envisaging outside evaluation bodies and security researchers testing and auditing open models.