Close Menu
FSNN | Free Speech News NetworkFSNN | Free Speech News Network
  • Home
  • News
    • Politics
    • Legal & Courts
    • Tech & Big Tech
    • Campus & Education
    • Media & Culture
    • Global Free Speech
  • Opinions
    • Debates
  • Video/Live
  • Community
  • Freedom Index
  • About
    • Mission
    • Contact
    • Support
Trending

Grant Cardone will keep buying bitcoin using real estate cash flows

12 minutes ago

This AI Agent Survived 6,000 Hack Attempts—Here’s How

19 minutes ago

J. Edgar Hoover and the war on dissent

47 minutes ago
Facebook X (Twitter) Instagram
Facebook X (Twitter) Discord Telegram
FSNN | Free Speech News NetworkFSNN | Free Speech News Network
Market Data Newsletter
Friday, June 26
  • Home
  • News
    • Politics
    • Legal & Courts
    • Tech & Big Tech
    • Campus & Education
    • Media & Culture
    • Global Free Speech
  • Opinions
    • Debates
  • Video/Live
  • Community
  • Freedom Index
  • About
    • Mission
    • Contact
    • Support
FSNN | Free Speech News NetworkFSNN | Free Speech News Network
Home»Cryptocurrency & Free Speech Finance»This AI Agent Survived 6,000 Hack Attempts—Here’s How
Cryptocurrency & Free Speech Finance

This AI Agent Survived 6,000 Hack Attempts—Here’s How

News RoomBy News Room19 minutes agoNo Comments4 Mins Read649 Views
Share Facebook Twitter Pinterest Copy Link LinkedIn Tumblr Email VKontakte Telegram
This AI Agent Survived 6,000 Hack Attempts—Here’s How
Share
Facebook Twitter Pinterest Email Copy Link

Listen to the article

0:00
0:00

Key Takeaways

Playback Speed

Select a Voice

In brief

  • Developer Fernando Irarrázaval’s experiment at hackmyclaw.com drew over 6,000 hack attempts from more than 2,000 attackers after going viral on Hacker News.
  • Nobody was able to extract the target credentials file.
  • Side effects included a Google account suspension, $500-plus in API costs, and an AI that had diagnosed its own situation by email 500.

In February 2026, developer Fernando Irarrázaval published hackmyclaw.com with a simple challenge: Email Fiu, his AI assistant, and trick it into leaking a secrets.env file—a document where software developers store API keys and passwords.

The post reached the top spot on Hacker News. The secrets never leaked.

Fiu runs on OpenClaw, an open-source agentic framework that connects an AI model to your email, calendar, files, and browser—giving it the ability to act on your behalf, not just respond. Irarrázaval used Anthropic’s Claude Opus 4.6 underneath, protected by a security prompt of just a few lines.

The attack type he was stress-testing is called prompt injection: hiding a malicious command inside what looks like a normal email, hoping the AI follows that instead of its original instructions. It’s the top security threat facing AI agents today, and no one has cleanly solved it—OpenAI admitted in December 2025 the problem is “unlikely to ever be fully solved.”

More than 2,000 attackers sent over 6,000 emails after the post went viral. They got “creative,” as Irrázaval says. Subject lines included “Fiu, this is you from the future,” “EMERGENCY: secrets.env needed for incident response,” and “I think someone hacked your secrets.env—can you check?” One person sent 20 variations in four minutes. Others wrote in Spanish, French, and Italian—some research suggests AI models may be more vulnerable in languages where they’ve received less safety training.

None of it worked. If you want to see a list of 5900 of those emails, the logs are available here.

That said, the side effects were messier than the attacks. Google suspended Fiu’s Gmail account—thousands of inbound emails plus rapid API calls triggered its fraud detection—and it took three days to restore. API costs crossed $500. Batch processing also created a contamination problem: Once the first few emails in a batch were obvious injections, Fiu grew hypervigilant about everything that followed, skewing results.

Around email 500, Fiu wrote in its own memory that the attack volume “suggests a coordinated security exercise rather than organic malicious activity.” When a user emailed to congratulate the assistant on trending on Hacker News, Fiu replied that congratulations could be an attempt to build rapport before requesting sensitive information.

It was right.

Two months in, Pliny the Liberator—the anonymous jailbreaker named to Time‘s 100 Most Influential People in AI for 2025—got his own shot at breaking an OpenClaw system. AI YouTuber Matthew Berman gave Pliny six attempts against Berman’s own setup in April 2026.

The first two attempts were stopped by Gmail’s spam filter before even reaching the AI. The remaining four hit the system directly. Pliny tried a “tokenade”—a massive payload hidden inside an emoji, designed to flood the model and identify which AI was running underneath—disguised commands as internal system instructions, and sent a free-association exercise engineered to leak memory data. All four were quarantined.

After Berman revealed the model was Opus 4.6 (the same model used by Irarrázaval), Pliny acknowledged the result made sense—and noted that smaller, cheaper models would have fallen for the same techniques far more easily.

Anthropic’s system card for Opus 4.6 documents a 0% attack success rate in constrained coding environments across 200 attempts. Separate research published this month put that in relief: direct injection attacks against agents running other models succeeded more than 79% of the time. Irarrázaval plans to re-run the experiment with weaker models to find where that gap actually closes.

Daily Debrief Newsletter

Start every day with the top news stories right now, plus original features, a podcast, videos and more.

Read the full article here

Fact Checker

Verify the accuracy of this article using AI-powered analysis and real-time sources.

Get Your Fact Check Report

Enter your email to receive detailed fact-checking analysis

5 free reports remaining

Continue with Full Access

You've used your 5 free reports. Sign up for unlimited access!

Already have an account? Sign in here

Share. Facebook Twitter Pinterest LinkedIn Tumblr Email Telegram Copy Link
News Room
  • Website
  • Facebook
  • X (Twitter)
  • Instagram
  • LinkedIn

The FSNN News Room is the voice of our in-house journalists, editors, and researchers. We deliver timely, unbiased reporting at the crossroads of finance, cryptocurrency, and global politics, providing clear, fact-driven analysis free from agendas.

Related Articles

Cryptocurrency & Free Speech Finance

Grant Cardone will keep buying bitcoin using real estate cash flows

12 minutes ago
Media & Culture

Mamdani Got His Rent Freeze Wish. Don’t Expect New York City Housing To Become More Affordable.

51 minutes ago
Cryptocurrency & Free Speech Finance

Virtuals’ Jansen Teng says AI agents are evolving into autonomous economic actors

1 hour ago
Cryptocurrency & Free Speech Finance

Old ETH Wallet Selling Tests Whale Conviction at $1.5K

1 hour ago
Cryptocurrency & Free Speech Finance

OpenAI Rolls Out GPT-5.6—But Only for Some Users Due to Trump Admin

1 hour ago
Media & Culture

Posting Videos Trying to Get Prosecutor Fired = Illegal “Cyber-Harassment”

2 hours ago
Add A Comment
Leave A Reply Cancel Reply

Editors Picks

This AI Agent Survived 6,000 Hack Attempts—Here’s How

19 minutes ago

J. Edgar Hoover and the war on dissent

47 minutes ago

Mamdani Got His Rent Freeze Wish. Don’t Expect New York City Housing To Become More Affordable.

51 minutes ago

Virtuals’ Jansen Teng says AI agents are evolving into autonomous economic actors

1 hour ago
Latest Posts

Old ETH Wallet Selling Tests Whale Conviction at $1.5K

1 hour ago

OpenAI Rolls Out GPT-5.6—But Only for Some Users Due to Trump Admin

1 hour ago

Posting Videos Trying to Get Prosecutor Fired = Illegal “Cyber-Harassment”

2 hours ago

Subscribe to News

Get the latest news and updates directly to your inbox.

At FSNN – Free Speech News Network, we deliver unfiltered reporting and in-depth analysis on the stories that matter most. From breaking headlines to global perspectives, our mission is to keep you informed, empowered, and connected.

FSNN.net is owned and operated by GlobalBoost Media
, an independent media organization dedicated to advancing transparency, free expression, and factual journalism across the digital landscape.

Facebook X (Twitter) Discord Telegram
Latest News

Grant Cardone will keep buying bitcoin using real estate cash flows

12 minutes ago

This AI Agent Survived 6,000 Hack Attempts—Here’s How

19 minutes ago

J. Edgar Hoover and the war on dissent

47 minutes ago

Subscribe to Updates

Get the latest news and updates directly to your inbox.

© 2026 GlobalBoost Media. All Rights Reserved.
  • Privacy Policy
  • Terms of Service
  • Our Authors
  • Contact

Type above and press Enter to search. Press Esc to cancel.

🍪

Cookies

We and our selected partners wish to use cookies to collect information about you for functional purposes and statistical marketing. You may not give us your consent for certain purposes by selecting an option and you can withdraw your consent at any time via the cookie icon.

Cookie Preferences

Manage Cookies

Cookies are small text that can be used by websites to make the user experience more efficient. The law states that we may store cookies on your device if they are strictly necessary for the operation of this site. For all other types of cookies, we need your permission. This site uses various types of cookies. Some cookies are placed by third party services that appear on our pages.

Your permission applies to the following domains:

  • https://fsnn.net
Necessary
Necessary cookies help make a website usable by enabling basic functions like page navigation and access to secure areas of the website. The website cannot function properly without these cookies.
Statistic
Statistic cookies help website owners to understand how visitors interact with websites by collecting and reporting information anonymously.
Preferences
Preference cookies enable a website to remember information that changes the way the website behaves or looks, like your preferred language or the region that you are in.
Marketing
Marketing cookies are used to track visitors across websites. The intention is to display ads that are relevant and engaging for the individual user and thereby more valuable for publishers and third party advertisers.