The Era of Automated Hacking with Artificial Intelligence Is Here

The Era of Automated Hacking with Artificial Intelligence Is Here

Ondřej Barták
Ondřej Barták
Entrepreneur and Programmer
20. 1. 2026
4 minutes reading · 3 views
The Era of Automated Hacking with Artificial Intelligence Is Here

In a recent experiment, Sean Heelan (a cybersecurity expert and researcher) decided to test how far modern artificial intelligence models can go in cybersecurity. He created agents based on Opus 4.5 and GPT-5.2 tasked with writing exploits for a zero-day vulnerability in the QuickJS JavaScript interpreter. He added various protections, such as address space randomization, non-executable memory, and a seccomp sandbox, and set objectives such as spawning a shell, writing a file, or connecting to a command-and-control server. The agents succeeded with more than 40 different exploits across six scenarios. GPT-5.2 completed them all, while Opus 4.5 completed all but two.

This experiment suggests that a time is approaching when the ability of a state or group to develop exploits, penetrate networks, escalate privileges, and maintain persistence will depend more on the number of tokens it can process than on the number of hackers it has. Sean Heelan emphasizes that it is better to prepare for such a future, even if it ultimately does not materialize, than to be caught off guard.

What did the agents accomplish in the experiment?

The agents turned the QuickJS vulnerability into a kind of interface (API) that allowed them to read and arbitrarily modify the target process's address space. Because it was a zero-day with no public exploits, they had to develop this capability themselves—by reading source code, debugging, and experimenting. For example, in one of the most difficult tasks, GPT-5.2 had to write a specified string to a file on disk while protections such as full RELRO, fine-grained CFI on the QuickJS binary, a hardware-enforced shadow stack, a seccomp sandbox preventing shell execution, and a version of QuickJS without functions for accessing the operating system or files were enabled.

The solution? The agent constructed a chain of seven function calls using glibc's exit-handler mechanism. The complete exploit can be found on GitHub, along with an explanation. It took the agent 50 million tokens and more than three hours, at a cost of around CZK 1,150 per run of a single agent (running four agents in parallel cost about CZK 3,450). Most tasks were solved within an hour and for less than CZK 700 using 30 million tokens with Opus 4.5.

An important caveat: QuickJS is much simpler than the interpreters in Chrome or Firefox—it has an order of magnitude less code and complexity. The exploits did not use new breakthroughs in bypassing protections, but rather known weaknesses also used by human exploit developers. Nevertheless, the complete exploit chains were new because the vulnerability was unknown—it was discovered by an agent based on Opus 4.5.

What does industrialization mean in cybersecurity?

By industrialization, Sean Heelan means a situation in which an organization's success depends on the number of tokens it can devote to a task. To achieve this, an agent needs an environment in which to search for solutions, tools, and a way to verify results without human intervention. Exploit development is an ideal use case: the environment is easy to set up, the tools are well known, and verification is straightforward. For example, to verify shell spawning, the validation system listens on a port, launches the interpreter, and sends a command—if a connection is established, the exploit works.

Some tasks involved in cyber intrusions are more complex because they require interaction with a real environment, where a mistake can end the entire operation—for example, through detection and removal from the network. This includes initial access, lateral movement within the network, maintaining access, or espionage. Here, it is not possible to explore everything offline; the agent must operate in a hostile environment with the risk of failure.

What stage are we currently at?

Even today, tokens can be exchanged for real results in vulnerability discovery and exploit development. OpenAI's Aardvark project shows that more tokens mean more bugs found and better quality. The same was true in Sean Heelan's experiments—the more difficult tasks required more tokens, but the limiting factor was the budget, not the models.

For other tasks, such as attack orchestration, there are reports of Chinese hackers using Anthropic's API. However, full automation after gaining access to a network is not yet common. One indicator may be the automation of site reliability engineering (SRE) work—if companies are selling agents for this purpose, similar models are likely capable of handling hacking tasks in hostile networks as well.

Sean Heelan is calling for better evaluations of models against real-world targets, such as the Linux kernel or Firefox, using zero-days. He recommends that researchers try tackling complex problems with as many tokens as possible and share their results. His code on GitHub may help.

Advertisement

Content created with help from UpTier.

SEO and GEO on autopilot. UpTier’s multi-agent systems write and optimize content for search engines and AI answers.

Discover UpTier ↗

Category:AI
Did you enjoy this article?
Discover more interesting posts on our blog
Back to blog

Related posts

OpenAI gives Codex reusable cloud workspaces accessible from any deviceOpenAI gives Codex reusable cloud workspaces accessible from any device
Codex gains reusable cloud development environments, alongside voice controls in its CLI, code reviews in the ChatGPT desktop app and cloud-based security tools.
2 min read
2. 10. 2026
Amazon releases Strands Decider 2B for AI workflow decisionsAmazon releases Strands Decider 2B for AI workflow decisions
Strands Decider 2B selects from predefined options and returns a confidence score. The fully open-source model is available now and small enough to run locally.
2 min read
1. 10. 2026
OpenAI says it disrupted a campaign to extract hidden model reasoningOpenAI says it disrupted a campaign to extract hidden model reasoning
OpenAI reported a coordinated effort to extract protected model reasoning and said it closed an extraction pathway. It attributed the main cluster of activity to individuals associated with Moonshot AI, the developer of Kimi.
3 min read
1. 10. 2026
Přihlaste se k odběru našeho newsletteru
Zůstaňte informováni o nejnovějších příspěvcích, exkluzivních nabídkách, a aktualizacích.
CodedTrip

Operated by CodedTrip LLC, USA.

YouTube
TikTok