Google Caught the First AI-Written Hack in the Wild — It Cracked 2FA and Left Robot Fingerprints

:shield: Google Caught the First AI-Written Hack in the Wild — It Cracked 2FA and Left Robot Fingerprints

The bad guys taught a chatbot to write a working break-in tool. Then Google’s own robot caught it. Welcome to the arms race nobody voted for.

The receipts: Exploit-to-attack time dropped from 72 hours (2025) to 24 hours (2026). 28.3% of new bugs get attacked within a single day. 45,207 new software flaws logged Jan–late July alone — on pace to DOUBLE last year.

Google’s Threat Intelligence Group (GTIG report via The Record) just confirmed the thing everyone in security whispered about at 3 AM: a real cybercrime crew used AI to write a working zero-day — a hack for a hole nobody knew existed — that walks straight past two-factor login. And the AI left fingerprints all over the code.

🧩 Dumb Mode Dictionary (read this first, no shame)
Nerd Word What It Actually Means
Zero-day A secret hole in software nobody’s patched yet. Attackers get “zero days” of warning. Scariest kind.
Exploit The actual break-in tool/script that USES that hole. The crowbar, not the unlocked window.
2FA (two-factor) The “enter the code we texted you” step. Supposed to stop hackers who already have your password.
GTIG Google Threat Intelligence Group. The suits who watch hackers for a living.
LLM Large Language Model. The tech behind ChatGPT/Gemini. A very confident autocomplete.
CVE A public ID number for a known bug. Like a license plate for vulnerabilities.
📰 Right, so here's what's actually happening

Here’s the plain-English version, no jargon.

A known crime crew needed a tool to sneak past 2FA on some open-source admin software (the control panel a lot of websites run on). Instead of hiring a skilled coder, they asked an AI to write the break-in script for them.

And it worked. The AI spotted a lazy assumption baked into the login code — the software basically trusted that “if you got this far, you must be legit” — and wrote a Python script to abuse it.

  • Google’s quote: “Frontier LLMs are uniquely capable of identifying exactly this category of high-level logic flaw.”
  • Translation: the machine is scary-good at spotting the dumb trust mistakes humans leave in code.
  • This is the FIRST time Google’s confirmed an AI-built exploit actually caught in the wild, not a lab demo.

Kids these days don’t need to learn assembly. They just need a good prompt. ¯\_(ツ)_/¯

🤖 The robot fingerprints (this part's actually funny)

The exploit code was so obviously AI-written it was almost embarrassing. Analysts spotted the tells instantly:

  • Educational docstrings — the malware had polite little comments explaining what each part does. Real criminals don’t document their crimes for you.
  • Hallucinated CVSS scores — the AI made up official-looking severity ratings that don’t exist. Confident. Wrong. Very chatbot.
  • “Textbook Pythonic” structure — suspiciously clean, like a coding tutorial.
  • A separate malware strain (nicknamed LONGSTREAM) had 32 redundant checks for daylight saving time. The AI just kept re-asking itself the same thing. Nobody was driving.

So yeah — the future of cybercrime writes cleaner code than half the interns I’ve fired, and still can’t stop double-checking whether the clocks changed. ( ͡° ͜ʖ ͡°)

⚔️ Plot twist: Google's OWN AI is fighting back

Before you panic — the same tech cuts both ways.

Google built an AI agent called Big Sleep (from Project Zero + DeepMind) that hunts for unknown bugs. It found a critical hole in SQLite (CVE-2025-6965) — the tiny database sitting inside basically every phone and browser on Earth — that real attackers already knew about and were about to use.

Google: “We believe this is the first time an AI agent has been used to directly foil efforts to exploit a vulnerability in the wild.”

First AI to actually stop an attack mid-swing. So the scoreboard right now: robots writing break-ins, robots patching them. And us squishy humans stuck in the middle, refreshing the security blog. More from SecurityWeek.

📊 The receipts (why 'patch later' is now dead)
Metric 2025 2026
Time from bug → real attack ~72 hours ~24 hours
CVEs attacked within 1 day rare 28.3%
New flaws logged (Jan–late July) 45,207
Pace vs last year baseline ~2x

Source: Insurance Journal on AI flaw discovery. The old advice was “patch within a week.” That week is now a day. If you run anything internet-facing, “I’ll get to it Monday” is how you become a breach headline.

Cool. So a chatbot writes break-in tools now… Now What the Hell Do We Do? (ง •̀_•́)ง

padlock security

Right, here’s the fun part. When a new weird thing becomes possible, the money isn’t in doing crime — it’s in selling shovels to everyone freaking out about the crime. Five plays, mixed colors, each one a street-smart 22-year-old could START tomorrow with $0.

🪟 The Patch Window Sprint

GTIG basically published a shopping list of what AI attackers now target: 2FA logic, open-source admin panels, that SQLite hole. Every small business running those is scared and confused THIS WEEK. That’s your window.

Package a one-page “Emergency AI-Exploit Checklist” for a specific niche (dentists, indie e-commerce, local law firms) — the exact 5 things to patch, in order, no jargon. Charge for the peace of mind, not the tech.

:brain: Example: A 24-year-old IT tech in Manila scrapes the free CISA Known Exploited Vulns catalog, turns it into a plain-English “fix these 5 today” PDF for Shopify store owners, sells it in a Facebook group for $19 a pop. First week: 40 sales. Zero code written.

:chart_increasing: Timeline: First win in 3-5 days while the news is hot. Fades in ~4 weeks once the panic cools and the checklists get copied. Sprint, don’t stroll.

🕳️ The Robot-Fingerprint Spotter

The whole story is that AI-written code has TELLS — fake CVSS scores, tutorial comments, weird repetition. Freelancers and small dev shops are terrified of accidentally shipping AI-poisoned open-source code.

Become the person who audits a repo for “does this smell AI-generated / sketchy?” Not deep security — just the obvious tells anyone can learn from Google’s own report.

:brain: Example: A self-taught coder in Lagos reads GTIG’s public write-up, makes a checklist of the 8 AI-slop code smells, offers “$50 vibe-check on any dependency before you ship it” on Indie Hackers. Bundles it with a Semgrep free scan. Lands 3 recurring clients in month one.

:chart_increasing: Timeline: First client in ~1 week. Real ceiling in 2-3 months when the free tools automate the obvious tells. Bank it early, then upsell the survivors into monthly retainers.

📡 The Fear-Index Newsletter (but the boring version)

Everyone’s writing “AI SCARY!!” think-pieces. Nobody’s tracking the boring, useful signal: WHICH specific open-source tools got flagged this week, and whether a patch dropped yet. That’s a searchable database, not a hot take.

Combine the free NIST vuln feed + GitHub release notes into a dead-simple “is my tool safe today?” lookup. Free to search, paid to get an alert when YOUR stack lights up.

:brain: Example: A 26-year-old in Kraków wires the free NIST feed to a no-code tool like Softr into a searchable table, adds a $6/mo email alert. Posts it in 5 subreddits. 200 free users, 18 paying by week three. Picks-and-shovels, baby.

:chart_increasing: Timeline: First paying user in ~10 days. Plateau around month 4 unless you add real coverage. The alert feature is the sticky part — lead with it.

🎣 Bait the Suits (the 2FA myth-buster)

Half the internet still thinks “I have 2FA, I’m safe.” This story proves 2FA has LOGIC holes AI can find. That gap between what people believe and what’s true = your content moat.

Be the definitive plain-English “myths about 2FA” resource for non-techies — what it stops, what it DOESN’T, and the one free upgrade (passkeys / hardware keys) most people never turn on.

:brain: Example: A cybersecurity student in São Paulo builds a free “How safe is YOUR login?” quiz, ends it with an affiliate link to a YubiKey and a guide to free passkeys. Shares in parenting + small-biz groups (the scared crowd). Affiliate + a $9 “harden your accounts” mini-guide = steady side income.

:chart_increasing: Timeline: First sale in ~1 week. This one actually has legs — 6+ months — because the myth never fully dies. Slow burn, but it compounds.

🎰 The Open-Source Bug Bounty Ride-Along

Here’s the grey-hat-flavored (but fully legal) one. AI tools like Big Sleep find bugs FAST — but companies pay humans who REPORT them properly. Most self-taught folks don’t know legit bug bounties pay real cash for finding holes.

Learn to run a free AI-assisted scanner on programs that WELCOME it, then write clean reports. You’re not hacking — you’re doing homework the platforms beg for.

:brain: Example: A 22-year-old in Hyderabad runs free tools on HackerOne and Bugcrowd public programs, uses free LLM help to write tidy reports (the boring part most people skip). First valid low-severity bug: $150. Fifth month, a medium: $2,000. Fully above-board, résumé gold too.

:chart_increasing: Timeline: First payout in 3-6 weeks if you grind. No real “patch date” here — bounties don’t expire — but burnout hits ~month 3 if you don’t pick a narrow niche. Specialize to survive.

🛠️ Follow-Up Actions
If you want to… Do this
Check if your tool’s on the danger list Search the CISA KEV catalog (free)
Actually harden your own logins Turn on passkeys — free, phishing-proof
Read the source, not the hype The Record’s GTIG writeup
Learn legal hacking for pay Start on HackerOne’s free hacker resources
Scan your own code for AI slop Run Semgrep (free tier)

:high_voltage: Quick Hits

You Want You Do
:locked_with_key: Not get owned this week Patch anything internet-facing NOW, not Monday
:detective: Spot AI-written malware Look for fake CVSS scores + tutorial comments
:money_bag: Cash in on the panic Sell checklists/audits before the tools automate it
:brain: Understand the real threat 2FA has LOGIC holes — passwords + codes aren’t enough
:open_book: Go deeper Read SecurityWeek’s breakdown

The robots write the exploits, the robots catch the exploits, and the winner is whoever’s still awake at 3 AM reading the patch notes. Same as it ever was — just faster now.

2 Likes