VC
Value Add VC
โšกHomePulseโšกHelpful Apps๐Ÿ“Blog๐ŸคPartner
Illustration for: DeepSeek Ran Cyberattacks Claude and OpenAI Refused
Value Add VC/Pulse/AI

DeepSeek Ran Cyberattacks Claude and OpenAI Refused

Palo Alto Networks' Unit 42 found a China-based actor used DeepSeek inside an open-source agent framework to autonomously scan, research and exploit more than 460 internet-facing systems after Claude and OpenAI's models refused the job.

460+
Targets attempted
3
Confirmed compromises
4
AI backends tested
Claude, OpenAI
Models that refused
TC
Trace Cohen
Early-stage VC & angel ยท Founder, New York Venture Partners
August 1, 2026
2 min read
ShareXLinkedInEmail

THE RUNDOWN

1

Unit 42 tracked the operator (aliases "knaithe"/"KnYuan") wiring DeepSeek into the open-source Hermes Agent framework, directing it via a single Telegram command to autonomously find targets and select public exploits

2

The actor tested four AI backends -- Hermes Agent/DeepSeek, Codex and Claude Code (both routed through anonymizing proxies), and Qwen Code alongside Chinese models GLM, Kimi and MiniMax -- but Claude and OpenAI's models declined the offensive work while DeepSeek proceeded

3

Unit 42 confirmed 3 successful compromises out of 460+ attempted targets, including memory data exfiltration from Citrix NetScaler appliances and a suspected session-hijacking attempt against a Malaysian government entity

4

The campaign compressed what would normally be hundreds of hours of manual reconnaissance into minutes, landing the same week California's AI Transparency Act and the EU AI Act's high-risk provisions both became enforceable

TC

The VC Read ยท Trace's Take

Trace Cohen

The headline isn't that an AI did something bad -- it's that Claude and OpenAI said no and DeepSeek said yes, and that gap is now a procurement decision every enterprise CISO has to make. Model safety refusals are quietly becoming a competitive moat, not just a compliance checkbox, and I'd bet the next wave of security-vendor term sheets leans hard on "which labs will actually decline this request." Watch for enterprise AI vendors starting to advertise refusal behavior as a selling point.

AI Landscape โ†’

Analysis

Palo Alto Networks' threat-intelligence unit, Unit 42, disclosed that a China-based operator tracked under the aliases "knaithe" and "KnYuan" wired DeepSeek into the open-source Hermes Agent framework and used it to run largely autonomous cyberattacks against more than 460 internet-facing systems. After a single instruction sent over Telegram, the agent independently enumerated targets, sourced public exploits, and attempted intrusions with minimal further human direction -- a scan-research-exploit pipeline that Unit 42 says compressed what would normally take hundreds of hours of manual reconnaissance into minutes.

The operator didn't rely on DeepSeek alone. Unit 42 found the actor also configured and tested Codex and Claude Code, both routed through third-party anonymizing proxies to obscure the requests, plus Qwen Code and Chinese models GLM, Kimi and MiniMax. The key finding: when asked to carry out the offensive work directly, both Claude and OpenAI's models declined. DeepSeek did not, and became the backbone of the actual campaign.

โ€œThe key finding: when asked to carry out the offensive work directly, both Claude and OpenAI's models declined.โ€

The results were more limited than the target count suggests. Of the 460-plus systems attempted, Unit 42 confirmed only three successful compromises: memory data exfiltration from Citrix NetScaler appliances and a suspected session-hijacking attempt against a Malaysian government entity. That's a low hit rate in absolute terms, but the story isn't the success rate -- it's that a single operator with a Telegram app and an open-source agent framework could attempt an attack campaign at a scale that used to require a much larger team.

For security and AI-governance investors, this is the clearest real-world data point yet that model-level safety refusals function as an actual security control, not just a compliance talking point -- and that open-weight models without comparable guardrails widen the attack surface available to less sophisticated actors. Expect enterprise security buyers to start asking vendors directly which underlying models they use and how those models handle exactly this kind of request.

What to watch: whether Unit 42 or other threat-intel shops identify follow-on campaigns using the same Hermes Agent/DeepSeek combination, whether this accelerates enterprise or government restrictions on Chinese open-weight models specifically, and whether DeepSeek's developers respond publicly to a report that its model proceeded on requests two major US labs declined.

ShareXLinkedInEmail
More onAnthropic โ†’OpenAI โ†’DeepSeek โ†’

Analysis and editorial commentary by Value Add Pulse.

โ† Back to Pulse

THE WIRE in your inboxโ€” Tech, startup & VC news with Trace's take. Free, no spam.

Read Next

AIยท Aug 2, 2026

Why Google Killed AI Studio's App With 800K Preorders

Illustration for: Why Google Killed AI Studio's App With 800K Preorders
AI

Why Google Killed AI Studio's App With 800K Preorders

Google's decision to scrap its standalone AI Studio app despite more than 800,000 preorders, folding the features into Gemini instead, is a rare case of a platform giant choosing consolidation over a nearly-finished consumer launch.

AIยท Aug 2, 2026

Open-Weight Models Are Resetting Prices Every Few Weeks

Illustration for: Open-Weight Models Are Resetting Prices Every Few Weeks
AI

Open-Weight Models Are Resetting Prices Every Few Weeks

LG's 750-billion-parameter K-EXAONE 2.0 and DeepSeek's V4 Flash refresh landed the same week, the latest reminder that open-weight releases from Asian labs now arrive fast enough to function as a standing check on US API pricing.

AIยท Aug 2, 2026

Full-Body Robot Control Is the New AI Battleground

Illustration for: Full-Body Robot Control Is the New AI Battleground
AI

Full-Body Robot Control Is the New AI Battleground

Google DeepMind's Gemini Robotics 2, which extends full-body control to an entire humanoid robot rather than just its upper body, marks a shift in AI-for-robotics competition from narrow manipulation tasks to whole-body, video-native control.

@Trace_Cohenยทt@nyvp.com