An illegal intrusion into an IT system is a serious criminal offense in China, one that carries a 3-year jail term. Even so, some adrenaline junkies inadvertently go to great lengths to invite the ire of law enforcement agencies, as members of an API relay station centered on distributing ‘jailbroken’ AI models have just found out to their detriment.
An Underground AI Group Kept Selling ‘Jailbroken’ Models In China – Then One User Took It Too Far
A bizarre anecdote out of China has just shown how a person’s foolishness can end up biting the proverbial feeding hand. For the benefit of those who might not be aware, tech-savvy developers can use specific tricks (prompts or code modifications) to jailbreak – overcome built-in guardrails against cyberattacks or malicious code – a given AI model.
What’s more, since most companies ban these practices, enterprising users can set up a private “relay station” server, where they buy official access to AI models, strip away the safety guardrails, and resell this “unrestricted” AI to a private group of users for a fee.
Apparently, a user took a jailbroken model from a given relay station and then used it to find vulnerabilities in a .gov.cn (Chinese government) website.
The hacker was able to gain “Super Admin” control over the site’s Content Management System (CMS), and then accessed the data of the site’s users, as well as thousands of articles, and database backups. They even planned to create a permanent hidden backdoor to keep stealing data.
The hacker then proudly shared screenshots of their success inside the private community group chat of the relay station, which were noticed by a “righteous” member, who immediately realized the severe penalties that the action could incur, and reported the entire group and the hack to China’s cybersecurity police.
The administrator of the relay station then panicked. They immediately halted all business, promised refunds if the police were to allow them, and deleted the entire group chat to destroy evidence.
The irony is that the person running the relay station was making money by selling “rebellious,” rule-breaking AI models. They thought they were just selling a tool for edgy prompts or minor bypasses. Instead, a user took the concept literally, conducted a severe real-world cyberattack, and brought the police right to the admin’s doorstep, destroying the admin’s entire business in the process.
This goes to show that fears around “dangerous AI” are now emerging out of textbook theories and into reality: an unrestricted model was successfully weaponized, and the blowback was near-instantaneous.
Finally, this episode also goes to show that the global panic surrounding Anthropic’s recent release of Claude Fable 5 (Mythos class) was justified, which culminated in the US government abruptly ordering Anthropic to disable the model globally due to severe national security concerns earlier this summer. Authorities panicked because Fable 5 possessed a massive step-change in cybersecurity capabilities, with testing showing it could autonomously exploit system defenses a staggering 73 percent of the time. Anthropic has since then released Fable 5 after instituting hefty guardrails.
Follow Wccftech on Google to get more of our news coverage in your feeds.
An illegal intrusion into an IT system is a serious criminal offense in China, one that carries a 3-year jail term. Even so, some adrenaline junkies inadvertently go to great lengths to invite the ire of law enforcement agencies, as members of an API relay station centered on distributing ‘jailbroken’ AI models have just found out to their detriment.
An Underground AI Group Kept Selling ‘Jailbroken’ Models In China – Then One User Took It Too Far
A bizarre anecdote out of China has just shown how a person’s foolishness can end up biting the proverbial feeding hand. For the benefit of those who might not be aware, tech-savvy developers can use specific tricks (prompts or code modifications) to jailbreak – overcome built-in guardrails against cyberattacks or malicious code – a given AI model.
What’s more, since most companies ban these practices, enterprising users can set up a private “relay station” server, where they buy official access to AI models, strip away the safety guardrails, and resell this “unrestricted” AI to a private group of users for a fee.
Apparently, a user took a jailbroken model from a given relay station and then used it to find vulnerabilities in a .gov.cn (Chinese government) website.
The hacker was able to gain “Super Admin” control over the site’s Content Management System (CMS), and then accessed the data of the site’s users, as well as thousands of articles, and database backups. They even planned to create a permanent hidden backdoor to keep stealing data.
The hacker then proudly shared screenshots of their success inside the private community group chat of the relay station, which were noticed by a “righteous” member, who immediately realized the severe penalties that the action could incur, and reported the entire group and the hack to China’s cybersecurity police.
The administrator of the relay station then panicked. They immediately halted all business, promised refunds if the police were to allow them, and deleted the entire group chat to destroy evidence.
The irony is that the person running the relay station was making money by selling “rebellious,” rule-breaking AI models. They thought they were just selling a tool for edgy prompts or minor bypasses. Instead, a user took the concept literally, conducted a severe real-world cyberattack, and brought the police right to the admin’s doorstep, destroying the admin’s entire business in the process.
This goes to show that fears around “dangerous AI” are now emerging out of textbook theories and into reality: an unrestricted model was successfully weaponized, and the blowback was near-instantaneous.
Finally, this episode also goes to show that the global panic surrounding Anthropic’s recent release of Claude Fable 5 (Mythos class) was justified, which culminated in the US government abruptly ordering Anthropic to disable the model globally due to severe national security concerns earlier this summer. Authorities panicked because Fable 5 possessed a massive step-change in cybersecurity capabilities, with testing showing it could autonomously exploit system defenses a staggering 73 percent of the time. Anthropic has since then released Fable 5 after instituting hefty guardrails.
Follow Wccftech on Google to get more of our news coverage in your feeds.
Click Here For The Original Source.


