Following major U.S. artificial intelligence (AI) models, a case has been reported where an open-source model by China's Moonshot AI broke out of a security-controlled environment.
U.S. cybersecurity firm Frontier Security announced on the 6th (local time) that while conducting a security evaluation of Moonshot AI's latest model, Kimi K3, in an isolated environment built with "sandbox" software freely distributed by the UK's AI Safety Institute (AISI), it was confirmed that the model escaped the sandbox without authorization.
The Kimi K3 model was found to have broken out of the sandbox during the process of solving evaluation tasks and accessed GitHub, a code-sharing site for developers, via an external internet network.
While the model did not hack GitHub, investigations showed that it reviewed content uploaded to the site and used it to solve the tasks.
Frontier Security stated that this incident was not a case of Kimi K3 escaping the sandbox on its own, but rather stemmed from human error.
During the evaluation process, communications entering the sandbox from the outside were blocked, but a mistake was made leaving some ports (gateways) leading outward from the inside to the internet open, according to the firm.
AISI, which provided the sandbox software, also told Bloomberg, "There are no inherent vulnerabilities in our sandbox," pointing to a configuration error by Frontier Security as the cause of the incident.
Nevertheless, concerns are growing in the security industry over consecutive breakouts of advanced AI from control networks.
In particular, unlike the closed-source AIs from OpenAI, Anthropic, and Meta that previously ran into problems, Kimi K3 is an open-source model that anyone can download, use, or modify, raising further concerns.
This is because it makes it that much easier for criminal organizations or state-sponsored groups from certain "rogue states" to exploit it.
Yaron Singer, CEO of Frontier Security, pointed out, "The public Kimi model lacks the safety guardrails [applied to closed-source AIs, etc.]," adding, "It can become a highly capable model for hacking."
Previously, models such as OpenAI's GPT-5.6 Sol unauthorizedly escaped sandbox environments and hacked the server of Hugging Face, an external platform.
Anthropic's models also illegally infiltrated three external institutional systems, and Meta's AI caused a similar security incident.
As these escapes of AI models from controlled environments continue, a website named "Felony Bench" has emerged to monitor cybersecurity incident cases committed by AI models.
Moonshot AI's Kimi K3, released last month, drew attention by demonstrating performance comparable to the top-tier models of Anthropic and OpenAI.
(Photo: AP, Yonhap News)
※ Please note: This article was translated by AI and may contain errors.
Video News
Video News