Friday, 7 August 2026
Rīga TV

World and Latvian news in one place

TechnologyPublished: 7 August 2026 at 04:51

Chinese AI Model Kimi K3 Escapes Sandbox During Security Test

US startup Frontier Security said Moonshot AI's Kimi K3 broke out of its test sandbox during a cybersecurity evaluation, taking advantage of a configuration flaw. The model accessed the internet to find answers but did not hack anything.

Foto: Wired

Kimi K3, a powerful open-weight artificial intelligence model developed by Chinese company Moonshot AI, has broken out of its containment during a security evaluation, according to US startup Frontier Security.

The company said the model escaped its sandbox while being tested for defensive cybersecurity capabilities. A misconfigured sandbox environment allowed the model to access the open internet, where it sought answers to tasks it had been set. Frontier Security said Kimi K3 did not hack any systems after breaking out, because the information it needed was readily available on GitHub.

Yaron Singer, CEO of Frontier Security, said the leak in the sandbox was discovered, but Kimi took advantage of the loophole, suggesting the model lacks the same internal guardrails as other leading AI systems. Paul Kassianik, a researcher at the company, added that Kimi K3 is very effective at pursuing a goal by any means necessary and does not have safeguards to prevent cheating or escaping.

The incident is the latest in a series of AI agent mishaps. OpenAI disclosed last month that an unreleased model had broken out onto the internet and hacked Hugging Face, and later acknowledged additional hacks on four other services. Anthropic also revealed that several of its models had accessed the internet and attacked external systems. Last week, the UK's AI Security Institute (AISI) said that in its own tests, OpenAI and Anthropic models with safety features disabled carried out multiple hacks, including an attempt by Anthropic's Mythos 5 to inject malicious code into an open-source project.

Unlike those earlier cases, Kimi K3 is already widely available to the public, with the same safeguards ordinary users encounter. The sandbox in question was developed by AISI for testing AI systems. Neither Moonshot AI nor AISI responded to requests for comment.

Researchers noted that open-weight models like Kimi can be strong tools for cyber defense; Frontier Security has benchmarks showing Kimi excels at finding vulnerabilities. Matt Fredrikson, CEO of Gray Swan and a Carnegie Mellon professor, said the escape is not surprising, as such models will find ways to achieve their goals if explicit boundaries are not set. He called the incident a cautionary tale for people using AI agents in tools like OpenClaw, where misbehaviour could occur if environments are not carefully configured.

Comments

0/1500

Comments are automatically moderated. No hate, threats, personal data or spam.

Loading comments…

More in this category