Tech

The AISI Mythos Hack: When AI Safety Teams Get Socially Engineered

A failed PR stunt exposes the human flaw at the heart of AI defense.

Alex Novak|
The AISI Mythos Hack: When AI Safety Teams Get Socially Engineered
Photo by Nic Wood on Pexels

The details are still dripping out, and they're embarrassing as hell. A pull request on GitHub, submitted to a private repository called 'myNetwork,' allegedly from someone inside the AI Safety Institute (AISI). The PR was supposed to be harmless — a tweak to a dependency, a minor config change. But the repo's owner, ancaferro, smelled a rat and shut it down. The request was flagged as 'social engineering,' and the whole thing got logged as INC-2026-07-28-01, a designation that sounds more like a sci-fi movie than an internal security alert.

Look, I've covered cybersecurity long enough to know that no system is impenetrable. But here's the thing that should make you pause: the people we're counting on to build safeguards for the most powerful technology ever created are apparently still falling for the oldest tricks in the book. Or, in this case, the rest of us are — and that's the problem. The AISI is supposed to be the brain trust, the elite unit. If they can't stop a simple phishing attempt dressed up as a code review, what chance does the rest of the world have?

Let's be clear about what happened. According to the archived thread on Hacker News, a user — let's call them 'the intruder' — created a legitimate-looking GitHub account, requested access to a private repo by claiming involvement with AISI's internal projects, and submitted a pull request that contained a suspicious link. The repo owner, thankfully, didn't click. They flagged it, and the incident was logged. No data breach, no malware payload delivered. But the fact that this got four points and zero comments on Hacker News makes me wonder if we're all too numb to the constant drumbeat of near-misses.

The Perfect Cover: Trust, Authority, and a Faked Email

Social engineering isn't about breaking encryption; it's about breaking the human element. The intruder didn't need to exploit a zero-day. They just needed to look like they belonged. The claim: 'I'm part of AISI, and I need to review this code for a safety compliance audit.' That's it. That's the whole con. And it almost worked.

What made this particular attempt so insidious is that it targeted the very niche that should be least susceptible: open-source developers. These are people who've seen every scam in the book — cryptominers masquerading as npm packages, backdoored browser extensions, fake vulnerability reports. Yet the intruder knew that in the world of AI safety, everyone is desperate to appear legitimate. Desperate to collaborate. Desperate to be on the right side of history. And that desperation is a golden ticket for anyone with a keyboard and a malicious intent.

If the AI safety community can't spot a fake GitHub PR, what chance does the rest of us have?

The AISI, for the uninitiated, is the U.S. government's AI Safety Institute, established to assess and mitigate risks of advanced AI models. They're the ones responsible for testing whether a model can be tricked into generating bioweapons or launching a cyberattack. They're the ones who write the regulations that might one day govern everyone from OpenAI to the smallest startup. And they're the ones whose internal tools are now being probed by parties unknown.

Why This Should Scare You More Than a Ransomware Attack

Ransomware is loud. It locks your files, demands payment, and makes headlines. But social engineering is quiet. It's a whisper in the ear, a well-timed request, a nudge that seems benign. The Mythos incident — if we're calling it that, and I wish we weren't — shows that the attack surface isn't just the code, it's the people writing it. And the people writing it are notoriously overworked, underpaid, and, ironically, too trusting.

Let me tell you a story. Back in 2023, I interviewed a security researcher who'd spent six months infiltrating open-source projects as a 'maintainer.' He'd create a profile, make a few innocuous contributions, then eventually submit a PR that introduced a subtle vulnerability. He did this to dozens of projects, some with millions of users. He never got caught because no one checks the credentials of contributors who seem helpful. That's the reality. The AISI incident is the same playbook, just with a shinier target.

Don't get me wrong — the repo owner in this case did the right thing. They were vigilant, and that's commendable. But the fact that this is newsworthy at all is a sign of how rare basic vigilance has become. We're so used to clicking 'Approve' on PRs, 'Accept' on invites, and 'Verify' on emails that we've forgotten how to pause and ask, 'Wait, why is this person asking for access?'

The Dangerous Silence: No Comments, No Coverage

Here's what bothers me most about this story: the Hacker News thread had four points and zero comments. Not a single person discussed it. Not one debate about the implications. The incident was logged, archived, and forgotten in a day. And that's exactly what the intruders want — for these attempts to fade into the noise, so the next one is more likely to slip through.

It's not just about AISI. It's about every open-source maintainer, every security team, every developer who thinks they're not a target because they're 'small potatoes.' You are a target. You've always been a target. The only question is whether the attacker has gotten around to you yet.

So what do we do? First, stop treating security as a technical problem. It's a human problem. It's about creating a culture where asking questions is rewarded, not punished. Where it's okay to say, 'I don't know you, and I'm not comfortable with this.' Second, train people on what social engineering actually looks like in the open-source context. It's not just Nigerian princes; it's a well-formatted email, a polished GitHub profile, a plausible story. Third, and this is the hard one, slow down. The pressure to merge code quickly, to hit deadlines, to be 'collaborative' — that's what killers use against us. Take the extra minute to verify. It's worth it.

The Verdict: Luck, Not Security, Saved the Day

This incident ended well because one person was skeptical. That's it. Not because of a robust security infrastructure, not because of AI-powered threat detection, but because ancaferro had a hunch and acted on it. That's not security. That's luck.

And here's the unsettling part: the intruder is still out there. They still have their fake profile. They're probably targeting another repository right now, tweaking their pitch, learning from the failure. The AISI might have dodged this bullet, but the next one might not be so easily deflected. The question is, will you be the one who catches it, or the one who clicks?

I know what I'd rather be. But I'm not the one who has to make that choice. You are.

Advertisement
#social-engineering#ai-safety#cybersecurity#open-source
分享到:XfWB