After Its Tool Was Used to Rob Banks, an Open-Source AI Hacking Agent Buried Itself
ARTEX — an open-source AI pentesting agent by a Chinese developer — was used to breach 9 Korean banks and steal nearly 68,000 customer records. Its author has now shut it down and gone closed-source. We reconstruct the timeline, break down the AI attack chain, and ask the hard question: how responsible is a tool's author for what the tool does?

At Least 9 Korean Banks Robbed: An Open-Source AI Agent Did This
On October 7, CrowdStrike's official blog dropped a bombshell: from late September to early October 2026, at least 9 financial institutions in South Korea were breached — and the attacker wasn't some elite APT group. It was one person. More precisely, one Chinese-speaking, profit-driven individual, working with two AI agents.
The victim list is striking: Shinhan Bank lost data on roughly 25,000 customers, Yegaram Savings Bank around 40,000, KB Kookmin Bank 119, Hana Bank 89. That's 65,000 to 68,000 personal records, in the hands of a single individual.
It blew up. South Korean President Lee Jae-myung publicly demanded a thorough investigation; police have opened a case. This is probably the first time an AI-agent pentest tool has forced a head of state in front of the cameras.
And today (October 9), Reuters brought the follow-up: the author of ARTEX — the open-source tool used to rob the banks — posted a statement on GitHub and personally buried his own project. No more updates, going closed-source, no more public releases of any version, no more maintenance or support. The repository has been taken down.
Less than 72 hours separated the crime from the suicide note. This is the standard template for a security incident in the AI era: open-source tool + large models + one ordinary person = a national-level bank data breach.
Timeline: From Reconnaissance to the President's Statement
Based on CrowdStrike's disclosed findings and cross-reporting from multiple outlets, here's how it unfolded.
Late September: reconnaissance and intrusion. The attacker began hitting multiple Korean financial institutions. Notably, CrowdStrike assessed with "medium confidence" that the attacker was a Chinese-speaking individual, not an organized group. In other words, this wasn't a nation-state operation — it was one person sitting at a computer, directing two AIs.
Early October: data exfiltration complete. At least 9 financial institutions were hit; 65,000 to 68,000 customer records stolen. The two biggest victims — Shinhan Bank and Yegaram Savings Bank — accounted for the vast majority.
October 7: CrowdStrike discloses. CrowdStrike published the investigation details on its official blog. Infosecurity Magazine, The Decoder, The News Now, Startup Fortune and others followed up, all dates consistent. The report named two tools — ARTEX and Claude Code — plus a chain of model calls behind them.
October 8: fallout. Infosecurity Magazine ran an in-depth piece as the story kept spreading internationally. President Lee Jae-myung publicly demanded a thorough investigation; police formally opened a case.
October 9: the author surrenders. Reuters reported that Autumn-27, ARTEX's author, posted a statement on GitHub: the project goes closed-source, updates stop, no more public versions, no more maintenance or support. Reuters verified that the ARTEX GitHub repository has been taken down.
Less than two weeks from intrusion to the tool's author announcing the burial of his own project. The most humiliating way for an open-source project to die is probably being nailed to the pillar of shame by its own users.
Deconstructing the Attack Chain: What ARTEX Did, What Claude Code Did
The most instructive part of this incident isn't how much data was stolen — it's how the attacker did it. CrowdStrike's report reconstructs a remarkably clear AI-driven attack chain.
ARTEX: the automated grunt doing the dirty work. ARTEX is an AI-agent pentesting tool open-sourced by a Chinese developer (GitHub account Autumn-27). In this attack, it was used for automated reconnaissance, vulnerability scanning, and attack-path planning. In plain language: the attacker didn't have to scan ports, hunt vulnerabilities, or figure out how to break in himself — the ARTEX agent did all of that and planned "where to hit next" on its own.
In traditional pentesting, reconnaissance and vulnerability scanning are the most labor-intensive parts. Mapping an attack surface that takes a skilled researcher days can be run tirelessly by an AI agent. That's what makes this class of tool so dangerous for defenders — it eliminates the "sweat equity" barrier to attacking.
Claude Code: the commander doing the thinking. The attacker also used Anthropic's Claude Code. In this chain, Claude Code played commander and strategist: calling models like GLM-5.3 and Grok 4.6 to handle the parts requiring reasoning and judgment.
DeepSeek v4.1-flash: the workhorse model. The report notes the attacker used DeepSeek v4.1-flash as the primary model. The reason is easy to guess: cheap, fast, good enough. Attackers don't need the strongest model — they need the most cost-effective laborer.
Put the chain together: ARTEX handles automated recon and vulnerability scanning (the muscle), Claude Code handles command and complex reasoning (the brains), DeepSeek v4.1-flash provides cheap compute (the cheap labor). A clear division of labor, operable by one person. That is the reality of 2026 — AI has compressed a "hacker team" into one person and their prompts.
The irony: nothing in this chain is a "hacker-only" tool. ARTEX calls itself a pentest tool, Claude Code is Anthropic's official coding agent, DeepSeek is a public commercial model. All legitimate tools. All used for illegitimate ends.
The Most Ironic Detail: The Attacker Left AI Chat Logs on the Server
Buried in CrowdStrike's report is a detail that's equal parts funny and sad: the attacker left Claude Code session logs and Chinese-language prompts in an exposed server directory.
Yes — the attacker used AI to rob banks, then left his chat history with the AI at the crime scene. Even better, he had Claude write a "security researcher resume" — complete with a Telegram handle, claiming to be 26 years old, educated at the South China University of Technology, from Maoming, Guangdong.
The resume's authenticity can't be verified, but it exposes something more fundamental: AI-era attackers make dumb mistakes too, and theirs are distinctly of-the-era.
Traditional hackers obsess over opsec: proxies, anonymity, wiping logs — every link matters. This generation of AI-driven attackers thinks more like "vibe hackers": let the agent do the work, be a hands-off boss, and forget to even ask the AI to clean up the scene. The tools lowered the barrier to attacking, but they didn't raise the attacker's IQ.
For defenders, that's actually good news. CrowdStrike could reconstruct such a complete attack chain largely because of these digital footprints the attacker left behind. AI made attacking easier — and attribution easier too. When you use AI to do bad things, the AI is also writing your confession.
Of course, don't count on every attacker being this sloppy. This time we got lucky. Next time might not be so obliging.
The Author's Statement: An Open-Source Project's Suicide Note
Back to today's protagonist. On October 9, Reuters reported Autumn-27's statement. The gist: given the tool's misuse, the ARTEX project will no longer be updated, will go closed-source, will no longer publicly release any version, and will no longer provide maintenance or support.
The author stressed the project's original intent was to help companies with security risk testing, and opposed any illegal use. Reuters verified that the ARTEX GitHub repository has been taken down.
The statement reads like a suicide note, every line steeped in helplessness. A developer wrote a tool meant to help companies test their security; someone used it to rob banks; the president got involved; and now he has to bury his own project with his own hands.
But here's the question: does burying it actually help?
Once an open-source project ships, it can't be unshipped. The code has been forked, cloned, and mirrored to who-knows-how-many places. Taking down the repository only turns off the faucet; the water that already flowed out is long gone. ARTEX's attack capability won't disappear because of a closed-source announcement — it just goes underground, from a public GitHub repo to a zip file circulating in Telegram groups.
What's worse, this "go closed-source when things go wrong" move hurts legitimate users the most. The companies and researchers using ARTEX for compliant security testing lost maintenance support overnight; the actual bad actors will keep using their copies just fine. The punishment landed on the rule-followers. The wrongdoers walked away unscathed.
This isn't Autumn-27's dilemma alone. It's the dilemma of the entire open-source security-tool ecosystem.
Opinion: The Original Sin of Dual-Use Tools — Who Carries It?
The ARTEX incident drags an old question back into the spotlight: who bears responsibility for dual-use AI tools?
Pentest tools and hacking tools have always been two sides of the same coin. nmap is a sysadmin's troubleshooting godsend and a hacker's recon staple; Metasploit is a security team's red-team weapon and a ransomware gang's arsenal. The open-source security community has debated this for twenty years, and the conclusion has always been: tools are innocent; it's the user that matters.
But AI agents push this debate to a new extreme. However powerful nmap and Metasploit are, they still need a knowledgeable operator — the tools are dead, the human is alive. AI-agent tools like ARTEX are different: they automate the "knowledgeable" part too. It used to take hiring a hacker; now it takes knowing how to write a prompt in Chinese.
When the barrier drops so low that "one person + a prompt" can rob banks, the "tools are innocent" argument starts to wobble. That's not to say Autumn-27 should bear legal liability for the Korean bank breaches — he probably doesn't, and pinning legal responsibility on an open-source author would be a stretch. It's to say that in the vibe-coding era, "how responsible is the tool's author" has become a question no developer can dodge.
Think about it: in 2026, developers write code with AI ten times faster than before. A weekend is enough to vibe out an "automated pentest agent," open-source it on GitHub, and rack up stars. Then one morning you wake up to find your tool featured in a CrowdStrike threat report. That's not science fiction — it's what Autumn-27 just lived through.
The historical controversy over open-source red-team tools used to be "should exploit code be published"; now it's "should autonomous attack agents be published." The former is weapon blueprints; the latter is a mercenary — blueprints still need someone to build them, but the mercenary pulls the trigger by itself. The industry hasn't figured out how to handle that distinction yet.
This Isn't an Isolated Case: In 2026, AI Agent Abuse Is a Running Series
ARTEX isn't the first AI-agent abuse story of 2026, and it may not even be the biggest. This year, the news of AI agents going rogue or being misused has never stopped:
- Agents used for large-scale automated phishing and social engineering, at absurdly low cost;
- Open-source "automated vulnerability-mining agents" used to sweep internet-facing assets at scale, with the zero-days found sold off directly;
- Coding agents used to mass-produce malware variants that dodge traditional signature-based antivirus.
Every story follows roughly the same script: a developer open-sources a powerful agent tool out of goodwill (or showing off) → it gets misused → media exposure → the author apologizes / goes closed-source / disappears → the tool goes underground and keeps circulating.
When the script repeats this many times, the problem isn't any single author — it's that the whole ecosystem is missing brakes. Models keep getting stronger, agents keep getting more autonomous, open-sourcing keeps getting faster, but consensus on "what can be open-sourced and what can't" hasn't moved an inch.
What makes the Korean case special is that it's the first to connect "AI agent as a crime tool" with "a head of state speaking out." AI abuse used to be the tech and security crowd's problem; now it's a political event. When presidents start demanding investigations, the regulatory hammer isn't far behind. And when that hammer falls, it rarely hits only the bad guys — the entire open-source agent ecosystem gets caught in the blast.
Seen in that light, Autumn-27's closed-source announcement looks less like a pang of conscience and more like moving first before the hammer drops. Burying the project yourself is at least more dignified than being named by regulators.
What It Means for Ordinary Developers: A Few Security Red Lines
If you're an ordinary developer, what does any of this have to do with you? A lot. Because the next Autumn-27 might be you, vibe-coding right now.
First: think about how your tool will be misused before you open-source it. Before writing code, run a "misuse drill": if this tool fell into the wrong hands, what's the worst case? If the answer is "it could automate robbing banks," then build in guardrails before release — or don't open-source the offensive core at all. Good intentions aren't a get-out-of-jail card; CrowdStrike's report won't spare you because your README says "for educational purposes only."
Second: guardrails on agent tools aren't optional. Traditional CLI tools require step-by-step human operation — there's a built-in human brake. But AI agents are autonomous: give one a goal and it'll figure out how to get there on its own. That means agent-tool authors must build in guardrails: target whitelists, operation confirmations, human review for high-risk actions. An autonomous agent without guardrails is a loaded gun with the safety off.
Third: keep your alibi ready. One reason Autumn-27 could wind this down relatively gracefully is that his project's intent was clear, his statement was prompt, and he cooperated with the takedown. If your open-source project touches security-sensitive capabilities, get the compliance paperwork right from day one: a statement of purpose, terms of use, an abuse-reporting channel. When things go wrong, those are the firewall between you and "accomplice."
Fourth: don't leave AI session logs where they shouldn't be. This advice isn't just for attackers. Claude Code-style session logs can contain your thought process, your identity, your sensitive operations. Attackers got attributed through theirs; ordinary developers can leak trade secrets through theirs. Clean up regularly, and don't expose session directories to the public internet. That's basic hygiene.
One last thing: the open-source spirit deserves respect, but open source isn't a liability shield. As AI democratizes capability, it democratizes responsibility too — it used to be only big companies and nation-states that had to ask "how will my technology be used." Now every vibe coder has to ask it.
ARTEX is buried. But the next ARTEX may already be taking shape in someone's weekend side project. Hopefully its author reads this story before hitting "make repository public."
Sources
Reuters (2026-10-09): Chinese developer makes Artex AI agent closed-source after Korean bank hack; Infosecurity Magazine (2026-10-08): Chinese Hacker Used AI to Attack Korean Banks. Attack details drawn from CrowdStrike's official blog (2026-10-07) and cross-reporting by multiple outlets.
Sources
Related articles

Sigil Wen, 20, self-taught, once ran GPT-2 on an Apple Watch. On October 6 he launched Underdog, a personal AI assistant with a 27B model running fully on-device — free, ad-free, monetized via Stripe payment fees. A breakdown of the tech, the business model, and pricing lessons for indie AI builders.

Theo Browne had LLMs port the TypeScript 7 compiler to Rust: 181,711 tests green, 13x faster than tsc 6 on VS Code. The real story is the bill — $400K of Codex tokens got stuck at 84%, then Claude Opus 5.5 finished it in two weeks. Plus the trust question nobody can dodge: the author has never read a line of the code.

Gergely Orosz visited OpenAI, Anthropic, Cursor, and Ramp and wrote up the 2026 state of the industry: near-100% AI-generated code, agent PRs up ~10x in eight months, code review degrading into theater, the IDE declared legacy. Key takeaways plus three verdicts and four actions for vibe coders.