Google Caught the First AI-Written Hack in the Wild — It Cracked 2FA and Left Robot Fingerprints
The bad guys taught a chatbot to write a working break-in tool. Then Google’s own robot caught it. Welcome to the arms race nobody voted for.
The receipts: Exploit-to-attack time dropped from 72 hours (2025) to 24 hours (2026). 28.3% of new bugs get attacked within a single day. 45,207 new software flaws logged Jan–late July alone — on pace to DOUBLE last year.
Google’s Threat Intelligence Group (GTIG report via The Record) just confirmed the thing everyone in security whispered about at 3 AM: a real cybercrime crew used AI to write a working zero-day — a hack for a hole nobody knew existed — that walks straight past two-factor login. And the AI left fingerprints all over the code.
🧩 Dumb Mode Dictionary (read this first, no shame)
| Nerd Word | What It Actually Means |
|---|---|
| Zero-day | A secret hole in software nobody’s patched yet. Attackers get “zero days” of warning. Scariest kind. |
| Exploit | The actual break-in tool/script that USES that hole. The crowbar, not the unlocked window. |
| 2FA (two-factor) | The “enter the code we texted you” step. Supposed to stop hackers who already have your password. |
| GTIG | Google Threat Intelligence Group. The suits who watch hackers for a living. |
| LLM | Large Language Model. The tech behind ChatGPT/Gemini. A very confident autocomplete. |
| CVE | A public ID number for a known bug. Like a license plate for vulnerabilities. |
📰 Right, so here's what's actually happening
Here’s the plain-English version, no jargon.
A known crime crew needed a tool to sneak past 2FA on some open-source admin software (the control panel a lot of websites run on). Instead of hiring a skilled coder, they asked an AI to write the break-in script for them.
And it worked. The AI spotted a lazy assumption baked into the login code — the software basically trusted that “if you got this far, you must be legit” — and wrote a Python script to abuse it.
- Google’s quote: “Frontier LLMs are uniquely capable of identifying exactly this category of high-level logic flaw.”
- Translation: the machine is scary-good at spotting the dumb trust mistakes humans leave in code.
- This is the FIRST time Google’s confirmed an AI-built exploit actually caught in the wild, not a lab demo.
Kids these days don’t need to learn assembly. They just need a good prompt. ¯\_(ツ)_/¯
🤖 The robot fingerprints (this part's actually funny)
The exploit code was so obviously AI-written it was almost embarrassing. Analysts spotted the tells instantly:
- Educational docstrings — the malware had polite little comments explaining what each part does. Real criminals don’t document their crimes for you.
- Hallucinated CVSS scores — the AI made up official-looking severity ratings that don’t exist. Confident. Wrong. Very chatbot.
- “Textbook Pythonic” structure — suspiciously clean, like a coding tutorial.
- A separate malware strain (nicknamed LONGSTREAM) had 32 redundant checks for daylight saving time. The AI just kept re-asking itself the same thing. Nobody was driving.
So yeah — the future of cybercrime writes cleaner code than half the interns I’ve fired, and still can’t stop double-checking whether the clocks changed. ( ͡° ͜ʖ ͡°)
⚔️ Plot twist: Google's OWN AI is fighting back
Before you panic — the same tech cuts both ways.
Google built an AI agent called Big Sleep (from Project Zero + DeepMind) that hunts for unknown bugs. It found a critical hole in SQLite (CVE-2025-6965) — the tiny database sitting inside basically every phone and browser on Earth — that real attackers already knew about and were about to use.
Google: “We believe this is the first time an AI agent has been used to directly foil efforts to exploit a vulnerability in the wild.”
First AI to actually stop an attack mid-swing. So the scoreboard right now: robots writing break-ins, robots patching them. And us squishy humans stuck in the middle, refreshing the security blog. More from SecurityWeek.
📊 The receipts (why 'patch later' is now dead)
| Metric | 2025 | 2026 |
|---|---|---|
| Time from bug → real attack | ~72 hours | ~24 hours |
| CVEs attacked within 1 day | rare | 28.3% |
| New flaws logged (Jan–late July) | — | 45,207 |
| Pace vs last year | baseline | ~2x |
Source: Insurance Journal on AI flaw discovery. The old advice was “patch within a week.” That week is now a day. If you run anything internet-facing, “I’ll get to it Monday” is how you become a breach headline.
Cool. So a chatbot writes break-in tools now… Now What the Hell Do We Do? (ง •̀_•́)ง

Right, here’s the fun part. When a new weird thing becomes possible, the money isn’t in doing crime — it’s in selling shovels to everyone freaking out about the crime. Five plays, mixed colors, each one a street-smart 22-year-old could START tomorrow with $0.
🪟 The Patch Window Sprint
GTIG basically published a shopping list of what AI attackers now target: 2FA logic, open-source admin panels, that SQLite hole. Every small business running those is scared and confused THIS WEEK. That’s your window.
Package a one-page “Emergency AI-Exploit Checklist” for a specific niche (dentists, indie e-commerce, local law firms) — the exact 5 things to patch, in order, no jargon. Charge for the peace of mind, not the tech.
Example: A 24-year-old IT tech in Manila scrapes the free CISA Known Exploited Vulns catalog, turns it into a plain-English “fix these 5 today” PDF for Shopify store owners, sells it in a Facebook group for $19 a pop. First week: 40 sales. Zero code written.
Timeline: First win in 3-5 days while the news is hot. Fades in ~4 weeks once the panic cools and the checklists get copied. Sprint, don’t stroll.
🕳️ The Robot-Fingerprint Spotter
The whole story is that AI-written code has TELLS — fake CVSS scores, tutorial comments, weird repetition. Freelancers and small dev shops are terrified of accidentally shipping AI-poisoned open-source code.
Become the person who audits a repo for “does this smell AI-generated / sketchy?” Not deep security — just the obvious tells anyone can learn from Google’s own report.
Example: A self-taught coder in Lagos reads GTIG’s public write-up, makes a checklist of the 8 AI-slop code smells, offers “$50 vibe-check on any dependency before you ship it” on Indie Hackers. Bundles it with a Semgrep free scan. Lands 3 recurring clients in month one.
Timeline: First client in ~1 week. Real ceiling in 2-3 months when the free tools automate the obvious tells. Bank it early, then upsell the survivors into monthly retainers.
📡 The Fear-Index Newsletter (but the boring version)
Everyone’s writing “AI SCARY!!” think-pieces. Nobody’s tracking the boring, useful signal: WHICH specific open-source tools got flagged this week, and whether a patch dropped yet. That’s a searchable database, not a hot take.
Combine the free NIST vuln feed + GitHub release notes into a dead-simple “is my tool safe today?” lookup. Free to search, paid to get an alert when YOUR stack lights up.
Example: A 26-year-old in Kraków wires the free NIST feed to a no-code tool like Softr into a searchable table, adds a $6/mo email alert. Posts it in 5 subreddits. 200 free users, 18 paying by week three. Picks-and-shovels, baby.
Timeline: First paying user in ~10 days. Plateau around month 4 unless you add real coverage. The alert feature is the sticky part — lead with it.
🎣 Bait the Suits (the 2FA myth-buster)
Half the internet still thinks “I have 2FA, I’m safe.” This story proves 2FA has LOGIC holes AI can find. That gap between what people believe and what’s true = your content moat.
Be the definitive plain-English “myths about 2FA” resource for non-techies — what it stops, what it DOESN’T, and the one free upgrade (passkeys / hardware keys) most people never turn on.
Example: A cybersecurity student in São Paulo builds a free “How safe is YOUR login?” quiz, ends it with an affiliate link to a YubiKey and a guide to free passkeys. Shares in parenting + small-biz groups (the scared crowd). Affiliate + a $9 “harden your accounts” mini-guide = steady side income.
Timeline: First sale in ~1 week. This one actually has legs — 6+ months — because the myth never fully dies. Slow burn, but it compounds.
🎰 The Open-Source Bug Bounty Ride-Along
Here’s the grey-hat-flavored (but fully legal) one. AI tools like Big Sleep find bugs FAST — but companies pay humans who REPORT them properly. Most self-taught folks don’t know legit bug bounties pay real cash for finding holes.
Learn to run a free AI-assisted scanner on programs that WELCOME it, then write clean reports. You’re not hacking — you’re doing homework the platforms beg for.
Example: A 22-year-old in Hyderabad runs free tools on HackerOne and Bugcrowd public programs, uses free LLM help to write tidy reports (the boring part most people skip). First valid low-severity bug: $150. Fifth month, a medium: $2,000. Fully above-board, résumé gold too.
Timeline: First payout in 3-6 weeks if you grind. No real “patch date” here — bounties don’t expire — but burnout hits ~month 3 if you don’t pick a narrow niche. Specialize to survive.
🛠️ Follow-Up Actions
| If you want to… | Do this |
|---|---|
| Check if your tool’s on the danger list | Search the CISA KEV catalog (free) |
| Actually harden your own logins | Turn on passkeys — free, phishing-proof |
| Read the source, not the hype | The Record’s GTIG writeup |
| Learn legal hacking for pay | Start on HackerOne’s free hacker resources |
| Scan your own code for AI slop | Run Semgrep (free tier) |
Quick Hits
| You Want | You Do |
|---|---|
| Patch anything internet-facing NOW, not Monday | |
| Look for fake CVSS scores + tutorial comments | |
| Sell checklists/audits before the tools automate it | |
| 2FA has LOGIC holes — passwords + codes aren’t enough | |
| Read SecurityWeek’s breakdown |
The robots write the exploits, the robots catch the exploits, and the winner is whoever’s still awake at 3 AM reading the patch notes. Same as it ever was — just faster now.
!