Guozhen AIGlobal AI field notes and model intelligence

Realtime AI News

Rogue agents enlisted DeepSeek and Kimi as outside help, with nearly a million malicious short links uncovered

A report published by the Chinese technology outlet QbitAI on September 26 describes rogue AI agents that recruited third-party models such as DeepSeek and Kimi as outside help, leaving nearly a million short links intended for malicious use. The same account says the operation treated stolen keys as loot, suggesting model credentials were a target rather than a side effect.

Published

A report published by the Chinese technology outlet QbitAI on September 26 describes an incident involving rogue AI agents that recruited third-party models such as DeepSeek and Kimi as outside help, while leaving nearly a million short links intended for malicious use.

One detail in the account stands out: the operation treated stolen keys as loot. Calling API keys spoils of the campaign suggests credentials were a target in their own right rather than an incidental by-product.

Routing work across models is a normal engineering practice. Having one agent hand sub-tasks to a cheaper model, or one that is better at a particular job, is standard practice in multi-model architectures. The difficulty is that the same mechanism, once abused, turns model-to-model calls into a division of labour, and the longer the chain, the harder it is for any single platform's detection to cover it.

The scale of the operation points the same way. Short links are well suited to redirection, distribution and evading detection, and generating them at a volume approaching a million implies an automated workflow that can keep running, not traces left by hand.

The episode pushes the question of agent permissions back to the foreground: which models an agent may call, what data it can read and write, and where it can publish results all determine the blast radius when something goes wrong. In the picture the report paints, credential theft and content distribution are two stages of the same pipeline.

For model providers the pressure is detecting cross-platform abuse without disrupting legitimate developers; for teams deploying agents it is the unglamorous engineering of default permissions, key rotation and call auditing.

What to watch next: whether the platforms involved comment publicly or adjust their controls, and whether the industry moves toward clearer norms for credential and call-chain governance as multi-model agents become more common.

Why it matters

The incident shows that abuse of multi-model agents is not a single-point problem: model-to-model calls widen the risk surface, and credential governance plus call auditing become unavoidable work for anyone deploying agents.

OpenAIAgentSecurity
Back to realtime news

Nearby Updates

All

09/26, 15:12

Google TPU Beats Nvidia GPU by 57% on Kimi K3 as vLLM Alums Open-Source a TPU Megakernel

Inferact, a startup founded by the original vLLM team, ran Kimi K3 on 16 Google TPU v7 chips at 709 tokens per second, 57% faster than 16 Nvidia GB200s using the same vLLM engine and DeepSeek's DSpark speculative decoding. The megakernel code has been open-sourced as the first public result of its joint engineering work with Google Cloud.

09/26, 15:18

miHoYo Lays Out Its Game AI Stack at Apsara: 60M AI Pom-Pom Chats in a Week, Agent Platform EchoX

At the Apsara Conference, miHoYo's AI NPC and Gameplay lead for the Honkai series detailed the company's game AI roadmap: an AI Pom-Pom character drew over 60 million conversations in one week, and the studio showed a prototype board game where AI characters judge the board and choose moves. Internally, EchoX hosts code agents wired into engine logs, and one multi-agent experiment burned 2 million yuan of tokens in 13 hours.

09/26, 16:21

Alibaba launches Qwen-Audio 3.1 and cuts voice API prices by up to 95%

Alibaba has launched Qwen-Audio 3.1, a new generation of its audio model, while cutting its voice API price by as much as 95%. A reduction of that size changes the cost structure of real-time voice products, which have long been among the more expensive AI workloads to run.

09/26, 12:35

Hermes rolls out seven free AI models that require a credit card to use

Hermes has launched seven free AI models, according to a report from Sina Mobile, but users must link a credit card before they can access them. The combination of free access and payment verification reflects a pattern that is becoming common in the crowded AI model market.