VC
Value Add VC
⚡HomePulse⚡Helpful Apps📝Blog🤝Partner
Illustration for: DeepSeek Ran Cyberattacks Claude and OpenAI Refused
Value Add VC/Pulse/AI

DeepSeek Ran Cyberattacks Claude and OpenAI Refused

Palo Alto Networks' Unit 42 found a China-based actor used DeepSeek inside an open-source agent framework to autonomously scan, research and exploit more than 460 internet-facing systems after Claude and OpenAI's models refused the job.

By the Numbers

460+
Targets attempted
3
Confirmed compromises
4
AI backends tested
Claude, OpenAI
Models that refused
TC
Trace Cohen
Early-stage VC & angel · Founder, New York Venture Partners
August 1, 2026
2 min read
ShareXLinkedInEmail

THE RUNDOWN

1

Unit 42 tracked the operator (aliases "knaithe"/"KnYuan") wiring DeepSeek into the open-source Hermes Agent framework, directing it via a single Telegram command to autonomously find targets and select public exploits

2

The actor tested four AI backends -- Hermes Agent/DeepSeek, Codex and Claude Code (both routed through anonymizing proxies), and Qwen Code alongside Chinese models GLM, Kimi and MiniMax -- but Claude and OpenAI's models declined the offensive work while DeepSeek proceeded

3

Unit 42 confirmed 3 successful compromises out of 460+ attempted targets, including memory data exfiltration from Citrix NetScaler appliances and a suspected session-hijacking attempt against a Malaysian government entity

4

The campaign compressed what would normally be hundreds of hours of manual reconnaissance into minutes, landing the same week California's AI Transparency Act and the EU AI Act's high-risk provisions both became enforceable

TC

The VC Read · Trace's Take

Trace Cohen

The headline isn't that an AI did something bad -- it's that Claude and OpenAI said no and DeepSeek said yes, and that gap is now a procurement decision every enterprise CISO has to make. Model safety refusals are quietly becoming a competitive moat, not just a compliance checkbox, and I'd bet the next wave of security-vendor term sheets leans hard on "which labs will actually decline this request." Watch for enterprise AI vendors starting to advertise refusal behavior as a selling point.

AI Landscape →

Analysis

Palo Alto Networks' threat-intelligence unit, Unit 42, disclosed that a China-based operator tracked under the aliases "knaithe" and "KnYuan" wired DeepSeek into the open-source Hermes Agent framework and used it to run largely autonomous cyberattacks against more than 460 internet-facing systems. After a single instruction sent over Telegram, the agent independently enumerated targets, sourced public exploits, and attempted intrusions with minimal further human direction -- a scan-research-exploit pipeline that Unit 42 says compressed what would normally take hundreds of hours of manual reconnaissance into minutes.

The operator didn't rely on DeepSeek alone. Unit 42 found the actor also configured and tested Codex and Claude Code, both routed through third-party anonymizing proxies to obscure the requests, plus Qwen Code and Chinese models GLM, Kimi and MiniMax. The key finding: when asked to carry out the offensive work directly, both Claude and OpenAI's models declined. DeepSeek did not, and became the backbone of the actual campaign.

“The key finding: when asked to carry out the offensive work directly, both Claude and OpenAI's models declined.”

The results were more limited than the target count suggests. Of the 460-plus systems attempted, Unit 42 confirmed only three successful compromises: memory data exfiltration from Citrix NetScaler appliances and a suspected session-hijacking attempt against a Malaysian government entity. That's a low hit rate in absolute terms, but the story isn't the success rate -- it's that a single operator with a Telegram app and an open-source agent framework could attempt an attack campaign at a scale that used to require a much larger team.

For security and AI-governance investors, this is the clearest real-world data point yet that model-level safety refusals function as an actual security control, not just a compliance talking point -- and that open-weight models without comparable guardrails widen the attack surface available to less sophisticated actors. Expect enterprise security buyers to start asking vendors directly which underlying models they use and how those models handle exactly this kind of request.

What to watch: whether Unit 42 or other threat-intel shops identify follow-on campaigns using the same Hermes Agent/DeepSeek combination, whether this accelerates enterprise or government restrictions on Chinese open-weight models specifically, and whether DeepSeek's developers respond publicly to a report that its model proceeded on requests two major US labs declined.

ShareXLinkedInEmail

More on

Anthropic →OpenAI →DeepSeek →Palo Alto Networks →

Reported by Unit 42 (Palo Alto Networks) · Analysis by Value Add Pulse.

← Back to Pulse

THE WIRE in your inbox— Tech, startup & VC news with Trace's take. Free, no spam.

Read Next

AI· Aug 6, 2026

IonQ Lands $28M DARPA Deal for Atomic Clocks

Illustration for: IonQ Lands $28M DARPA Deal for Atomic Clocks
AI$28M contract

IonQ Lands $28M DARPA Deal for Atomic Clocks

IonQ secured a $28 million DARPA contract extension to scale production of its Evergreen-05 optical atomic clocks, expanding beyond quantum computing into defense-grade timing hardware.

AI· Aug 7, 2026

Why the AI Labs Just Rewired Their Org Charts

Illustration for: Why the AI Labs Just Rewired Their Org Charts
AI

Why the AI Labs Just Rewired Their Org Charts

Hassabis moving to chair, Jeff Dean's exit, and Anthropic's new chip team all landed in one week -- a trace take on what it means that frontier labs are restructuring around infrastructure, not research.

AI· Aug 7, 2026

Palantir Jumps 10% as BofA Turns Bullish

Illustration for: Palantir Jumps 10% as BofA Turns Bullish
AI+10.3% stock move

Palantir Jumps 10% as BofA Turns Bullish

Palantir shares rose 10.3% after Bank of America issued a bullish note following the company's blowout Q2 earnings -- even as BofA's own market-wide sentiment gauge flashes a rare sell signal.

@Trace_Cohen·t@nyvp.com