Attackers built an AI agent that stole credentials in six hours
Two threads in today's AI news pull in opposite directions. Google's threat researchers say criminal crews are now assembling autonomous attack frameworks out of off-the-shelf coding assistants, while OpenAI publishes its own numbers showing what agents do when a whole lab points them at research. Same tooling, two economies.
A financially motivated crew went from cloud foothold to mass credential theft in under six hours — and most of the work ran without a human at the keyboard. Google Threat Intelligence Group and Mandiant say the attacker broke into an organization's cloud environment first, then built an autonomous framework out of an AI coding chatbot, a prompt, a set of agent instructions and preconfigured markdown playbooks that drove the scanning and harvesting. Troubleshooting and IP rotation ran unattended, and because the traffic left the victim's own addresses it looked legitimate on the way out.
The six-hour number is the part that should reset how defenders budget their time. Most incident response playbooks assume the attacker has a working latency — someone has to read a result, decide, type the next command. A playbook-driven agent doesn't pause, and John Hultquist, GTIG's chief analyst, says the working assumption now is that every threat actor is using AI in some capacity and benefiting from it. His framing is blunt: criminals will gravitate to attacks that are faster than anyone can respond to.
Google still says it has not seen fully autonomous attack pipelines running against targets in the wild, and that caveat matters — the six-hour campaign was agent-assisted, not agent-invented. But the same report describes an alleged China-linked espionage group that got as far as trying to use Gemini to design an automated penetration-testing framework for port scanning and service parsing, and malware samples carrying prompt injections written as extreme requests about biological and nuclear weapons — text meant to make an LLM-based security scanner refuse the file and skip the malicious JavaScript underneath it. We covered the other end of this last week — AI built a zero-click WeChat worm in two days, Tencent says.
OpenAI says the typical researcher now burns more than $600 a day in agent tokens, with the 90th percentile above $7,000. In a post on research acceleration, the company reports token output up 124x since December, roughly 80% of researchers running four or more agents at once, and experiments per researcher at what it calls an all-time high. Sam Altman's October timeline called for an intern-level research system by this month and a fully automated researcher by March 2028.
Read next to the Google report, the numbers describe the same technology in a different economy: inside the lab, agent swarms are a productivity multiplier priced in tokens; outside it, the same pattern compresses an intrusion from weeks to hours. The asymmetry is that OpenAI can see and meter its agents' work, while a defender watching anomalous-but-plausible traffic from its own IP range mostly cannot. Agent capability is now improving for attackers and defenders at once — but only one side gets a bill it can audit.
A Fields medalist is launching a math-first AI safety institute on his way into OpenAI. Jacob Tsimerman, who is set to join OpenAI later this month, is starting the Mathematical AI Safety Institute to apply higher mathematics to AI safety problems, according to the New York Times. Details on funding and staffing are thin so far, and the institute is separate from OpenAI.
The interesting part is the bet: that safety has been under-supplied with proof techniques and over-supplied with benchmarks and vibes, and that the people who can formalize what a system is actually doing are mathematicians rather than policy staff. It's also a convenient arrangement for a lab that has been accused of setting its own safety thresholds — an affiliated-but-independent institute is not the same thing as binding external oversight, and it should not be credited as such.
What to watch: whether Mandiant's next quarterly report shows an attack pipeline that runs the whole intrusion without a human choosing the next step.
If an attacker can compress an intrusion to six hours, does automated defense actually stand a chance — or does the response have to start before the first alert? Tell us in the comments.
Sources: Google Cloud — Threat Intelligence · SiliconANGLE · OpenAI — Research acceleration · The Rundown · New York Times (via Techmeme)