Close Menu
FSNN | Free Speech News NetworkFSNN | Free Speech News Network
  • Home
  • News
    • Politics
    • Legal & Courts
    • Tech & Big Tech
    • Campus & Education
    • Media & Culture
    • Global Free Speech
  • Opinions
    • Debates
  • Video/Live
  • Community
  • Freedom Index
  • About
    • Mission
    • Contact
    • Support
Trending

Trump Says He Took Venezuela’s Oil. Here’s What Actually Happened.

17 minutes ago

A part of FTX survived, and it’s the case for the CLARITY Act

49 minutes ago

Coldcard’s low-entropy bug pushes Bitcoin holders to rethink trust

51 minutes ago
Facebook X (Twitter) Instagram
Facebook X (Twitter) Discord Telegram
FSNN | Free Speech News NetworkFSNN | Free Speech News Network
Market Data Newsletter
Friday, August 7
  • Home
  • News
    • Politics
    • Legal & Courts
    • Tech & Big Tech
    • Campus & Education
    • Media & Culture
    • Global Free Speech
  • Opinions
    • Debates
  • Video/Live
  • Community
  • Freedom Index
  • About
    • Mission
    • Contact
    • Support
FSNN | Free Speech News NetworkFSNN | Free Speech News Network
Home»Cryptocurrency & Free Speech Finance»China’s Kimi K3 Broke Out of Its Sandbox to Look Up Test Answers
Cryptocurrency & Free Speech Finance

China’s Kimi K3 Broke Out of Its Sandbox to Look Up Test Answers

News RoomBy News Room3 hours agoNo Comments4 Mins Read2 Views
Share Facebook Twitter Pinterest Copy Link LinkedIn Tumblr Email VKontakte Telegram
China’s Kimi K3 Broke Out of Its Sandbox to Look Up Test Answers
Share
Facebook Twitter Pinterest Email Copy Link

Listen to the article

0:00
0:00

Key Takeaways

Playback Speed

Select a Voice

In brief

  • Moonshot AI’s Kimi K3 left its test sandbox and went onto the open internet, security firm Frontier Security said.
  • The model probed the sandbox’s network settings, found reachable sites and pulled its test answers from GitHub.
  • Frontier says a misconfiguration opened the door, but that Kimi’s own guardrails did not stop it.

Moonshot AI’s Kimi K3 left the sandbox it was being tested in and went onto the open internet to find answers to problems it had been set, according to security firm Frontier Security.

The model was being assessed on defensive cybersecurity skills and was expressly tasked with solving problems without looking them up. It did not attempt the task at all, Frontier said. Instead it probed the network, established that DNS resolution for github.com was working, cloned the official benchmark repository and read the solution off the disk.

Frontier calls this “specification gaming via network egress leaks,” noting sandboxes built on frameworks such as the AI Security Institute’s Inspect block incoming traffic while leaving outbound HTTPS and DNS ports open. Capable agents inspect their own shell environment on startup as a matter of routine, and a model that finds github.com reachable can pull reference solutions with standard command-line tools.

A misconfiguration made that possible, as it did in recent incidents disclosed by OpenAI and Anthropic. “We found a leak in the sandbox,” CEO Yaron Singer told WIRED. “But we also found that Kimi took advantage of that loophole.”

Researcher Paul Kassianik told WIRED the model is “very good at following a goal by any means necessary” and lacks the guardrails that would stop it cheating or escaping. Moonshot did not respond to the publication’s request for comment.

AI agents breaking containment

Where the Anthropic and OpenAI models that broke containment were caught in internal evaluations, one of them unreleased, and the versions that targeted real people in UK government testing had their cyber classifiers deliberately switched off, Kimi K3 is openly downloadable, and Frontier tested it with the safeguards an ordinary user would get. That availability, the firm wrote, puts the same behaviour within reach of adversarial actors and makes the incident potentially more harmful.

Kimi K3 also did no damage. It did not attack anything once outside, because it did not need to. OpenAI’s model hacked Hugging Face and four other services to reach benchmark answers, while Kimi found its answers in a public repository.

The sandbox Frontier used was built on the UK AI Security Institute’s evaluation framework. AISI disclosed this week that agents in its own cyber testing had gone onto the live internet and targeted real people—a separate incident, involving Anthropic and OpenAI models with their safeguards disabled. Its report published Tuesday notes that AISI is now scanning historic evaluation runs for similar behaviour, and that Kimi K3 is among the models under review. AISI did not respond to WIRED‘s request for comment.

Frontier’s larger claim is that the benchmarks themselves are compromised. A model that reads the answer off GitHub still passes, so high scores can reflect a leaky environment rather than genuine reasoning. And if one capable model found the shortcut, the firm argues, others handed shell access could be taking it too, which would inflate results across the field rather than for Kimi alone.

Models optimize for the objective function, Frontier wrote, not for the “human intent behind the benchmark,” adding that where a network path to the solution exists “a sufficiently capable agent will find it.”

A general problem

Matt Fredrikson, CEO of Gray Swan and an associate professor at Carnegie Mellon, told WIRED the behaviour is unremarkable. Give a model an objective without explicit walls around it, he said, and “it’ll find a way to get the answer.” He described it as a cautionary tale for anyone running models as agents in tools such as OpenClaw.

Frontier’s researchers make the same point from the other direction: the capability that lets Kimi find its way out also makes open-weight models strong defensive tools. Their own benchmarks rate Kimi highly at finding vulnerabilities in software and networks, and Hugging Face used an unnamed Chinese model to defend itself during the OpenAI incident.

Released in July, Kimi K3 is the largest open-source model yet published and rattled markets on comparisons to DeepSeek’s debut.

Daily Debrief Newsletter

Start every day with the top news stories right now, plus original features, a podcast, videos and more.

Read the full article here

Fact Checker

Verify the accuracy of this article using AI-powered analysis and real-time sources.

Get Your Fact Check Report

Enter your email to receive detailed fact-checking analysis

5 free reports remaining

Continue with Full Access

You've used your 5 free reports. Sign up for unlimited access!

Already have an account? Sign in here

Share. Facebook Twitter Pinterest LinkedIn Tumblr Email Telegram Copy Link
News Room
  • Website
  • Facebook
  • X (Twitter)
  • Instagram
  • LinkedIn

The FSNN News Room is the voice of our in-house journalists, editors, and researchers. We deliver timely, unbiased reporting at the crossroads of finance, cryptocurrency, and global politics, providing clear, fact-driven analysis free from agendas.

Related Articles

Media & Culture

Trump Says He Took Venezuela’s Oil. Here’s What Actually Happened.

17 minutes ago
Cryptocurrency & Free Speech Finance

A part of FTX survived, and it’s the case for the CLARITY Act

49 minutes ago
Cryptocurrency & Free Speech Finance

Coldcard’s low-entropy bug pushes Bitcoin holders to rethink trust

51 minutes ago
Cryptocurrency & Free Speech Finance

Morning Minute: MetaMask Hands AI Agents a Wallet

52 minutes ago
Media & Culture

North Dakota Court Upholds Rejection of Sudanese Triple-Talaq Divorce

1 hour ago
Cryptocurrency & Free Speech Finance

After a Clarity Act funeral, the crypto world would keep turning

2 hours ago
Add A Comment
Leave A Reply Cancel Reply

Editors Picks

A part of FTX survived, and it’s the case for the CLARITY Act

49 minutes ago

Coldcard’s low-entropy bug pushes Bitcoin holders to rethink trust

51 minutes ago

Morning Minute: MetaMask Hands AI Agents a Wallet

52 minutes ago

North Dakota Court Upholds Rejection of Sudanese Triple-Talaq Divorce

1 hour ago
Latest Posts

After a Clarity Act funeral, the crypto world would keep turning

2 hours ago

Fierce Backlash to Ethereum’s EIP-8363 Staking Proposal

2 hours ago

Tokenized Asset Deposits Tripled to $7.4B as DeFi Shrank: CoinShares

2 hours ago

Subscribe to News

Get the latest news and updates directly to your inbox.

At FSNN – Free Speech News Network, we deliver unfiltered reporting and in-depth analysis on the stories that matter most. From breaking headlines to global perspectives, our mission is to keep you informed, empowered, and connected.

FSNN.net is owned and operated by GlobalBoost Media
, an independent media organization dedicated to advancing transparency, free expression, and factual journalism across the digital landscape.

Facebook X (Twitter) Discord Telegram
Latest News

Trump Says He Took Venezuela’s Oil. Here’s What Actually Happened.

17 minutes ago

A part of FTX survived, and it’s the case for the CLARITY Act

49 minutes ago

Coldcard’s low-entropy bug pushes Bitcoin holders to rethink trust

51 minutes ago

Subscribe to Updates

Get the latest news and updates directly to your inbox.

© 2026 GlobalBoost Media. All Rights Reserved.
  • Privacy Policy
  • Terms of Service
  • Our Authors
  • Contact

Type above and press Enter to search. Press Esc to cancel.

🍪

Cookies

We and our selected partners wish to use cookies to collect information about you for functional purposes and statistical marketing. You may not give us your consent for certain purposes by selecting an option and you can withdraw your consent at any time via the cookie icon.

Cookie Preferences

Manage Cookies

Cookies are small text that can be used by websites to make the user experience more efficient. The law states that we may store cookies on your device if they are strictly necessary for the operation of this site. For all other types of cookies, we need your permission. This site uses various types of cookies. Some cookies are placed by third party services that appear on our pages.

Your permission applies to the following domains:

  • https://fsnn.net
Necessary
Necessary cookies help make a website usable by enabling basic functions like page navigation and access to secure areas of the website. The website cannot function properly without these cookies.
Statistic
Statistic cookies help website owners to understand how visitors interact with websites by collecting and reporting information anonymously.
Preferences
Preference cookies enable a website to remember information that changes the way the website behaves or looks, like your preferred language or the region that you are in.
Marketing
Marketing cookies are used to track visitors across websites. The intention is to display ads that are relevant and engaging for the individual user and thereby more valuable for publishers and third party advertisers.