Independent/Reader-funded/Infrastructure, not tokens
DeAINEWS

AI you control — open models, private inference, and the networks that run them.

PulseOpen-Weights Releases

Open-source ARTEX agent ran DeepSeek V4.1-Flash in bank hacks

X spent three days debating CrowdStrike's ARTEX report: an open-source pentest agent on DeepSeek V4.1-Flash hit South Korean banks, leaking 66,000 records.

DeAI is powered by Morpheus (mor.org). We cover competing providers on the same terms — see our methodology.

A lone rack server in a dim, sparse self-hosted server room lit by a single overhead bulb with amber status lights, standing in for the self-hosted ARTEX and open-model stack behind the South Korean bank intrusions. Illustration: DeAI
A lone rack server in a dim, sparse self-hosted server room lit by a single overhead bulb with amber status lights, standing in for the self-hosted ARTEX and open-model stack behind the South Korean bank intrusions. Illustration: DeAI

X spent October 6 through 8 relitigating the CrowdStrike report on the South Korean bank intrusions, with the debate fixated on whether AI agents "hacked the banks." The verified record underneath: at least seven financial firms breached, roughly 66,000 individuals' records exposed, and an open-source pentest agent running DeepSeek V4.1-Flash as its primary LLM backend.

Key facts

  • CrowdStrike Intelligence identified the open-source agentic pentest tool ARTEX, run with DeepSeek V4.1-Flash as its primary LLM backend and supplemented by GLM-5.3 and Grok 4.6, on infrastructure tied to the intrusions (CrowdStrike).
  • Korea Herald-reported figures: about 66,000 individuals' records plus 2,200 corporate records across seven financial services firms (GovInfoSecurity).
  • Shinhan Bank disclosed 25,729 customers affected; Hana Bank reported 89 (GovInfoSecurity).
  • The attacker's own Claude Code session logs, ARTEX configs, and memory files sat in open directories and provided CrowdStrike its roadmap (CrowdStrike).
  • South Korea's Financial Security Institute: "It is true that AI was used in the attacks, but the AI did not act independently without human involvement. A hacker used the AI as a tool" (GovInfoSecurity).
  • High X velocity across October 6-8, driven by amplification from @AndrewCurran_, @MaxForAI, and @business.

What's driving the conversation

The discourse split into three camps within a day of the wire coverage. The first treats this as the arrival of agentic hacking at scale: President Lee Jae Myung told his cabinet that "it's now become possible to use AI to hack with ease even without specialized skills," and that framing dominated the biggest amplification threads (The Record). Bloomberg's write-up of CrowdStrike's attribution, which landed October 8, pushed the same framing into finance and markets timelines.

The second camp pushes back on the agent framing. Korean officials and the Financial Security Institute say the AI was a tool under human direction, not an autonomous operator, and the CrowdStrike report itself reads that way: the sessions show a human asking Claude where to sell stolen Korean data, requesting a fake security-researcher resume, and directing vulnerability research. People arguing this side on X point out that the pentest agent automates known tradecraft; it does not invent attacks.

The third camp is arguing about the models, not the method: an open-source tool configured to call DeepSeek V4.1-Flash, GLM-5.3, and Grok 4.6 through a reseller reads, to some, as proof that open-weight models are the attacker's stack of choice. That inference outruns the report. CrowdStrike documents a tooling choice by one actor, and the same sessions used Claude Code as the orchestration layer.

The substance

What is verified: CrowdStrike Intelligence's October 7 report documents a two-server architecture, a Hong Kong-based primary host plus an ARTEX instance at a second IP, with Chinese-language pentesting prompts in a Claude Code markdown file on the ARTEX host. The report assesses with moderate confidence that the actor is a financially motivated Chinese speaker. It names the model stack, the proxy IPs, and the MITRE ATT&CK techniques, including T1588.007 (Obtain Capabilities: Artificial Intelligence).

What is attribution, not fact: no named adversary. The resume details recovered from the sessions, including a phone number, a Telegram handle, a birth date, and a university, "likely belong" to the attacker but cannot be definitively confirmed, per CrowdStrike. Reuters reported October 8 that the suspect may be a 26-year-old Chinese cybersecurity worker, resting on those same session details.

What is operational security failure, not AI capability: the single most consequential detail in the report is that the attacker left Claude Code session histories in open directories. The forensics were done for the defenders by the attacker's own logs. That is a lesson about opsec, not about what models can do.

On the tool itself: ARTEX is a free open-source agentic pentest platform by Chinese developer Li Puhua, alias Autumn, downloadable from GitHub since July and a winner of Baidu's "Agent+" attack-and-defense challenge in September (GovInfoSecurity). The original repository returned a 404 when we checked on October 9, while an English-UI fork stayed live. We make no claim about takedowns or renames; the repo's current unavailability is simply observed.

Why builders are watching

The story is not "hackers used AI." That is a month-old headline. The concrete datapoint for anyone shipping AI systems is that the attack stack was open-weight-first and self-hosted: a self-run ARTEX instance calling an open model through a reseller, orchestrated by a coding agent, on rented infrastructure. Two debates from our prior coverage land differently after this. The first is the one our backdoored open-weight model coverage raised: guardrails on open weights are defaults, not locks, and a self-hosted deployment inherits whatever the operator does or does not add. The second is that model telemetry ends at self-hosting. When the inference runs on rented GPUs behind a reseller, the provider sees prompts and can enforce policy; when it runs on the operator's own box, that enforcement surface disappears. Anthropic's GLM-5.3 red-team report framed the dual-use risk for open weights in the abstract; this incident supplies the first concrete production example of the pattern, with the caveat that the same session logs show Claude Code orchestrating it. Our explainer on abliterated and uncensored models covers the modification layer that makes refusal training a default rather than a guarantee.

Watch the Korean National Police Agency's 28-member task force for confirmed attribution, and watch whether CrowdStrike follows up with a named adversary tracking entry. The model-policy question worth tracking separately: whether API resellers face any obligation or capability review when a single customer account drives pentest agents at intrusion scale.

Questions

What actually happened in the South Korean bank hacks?
Between late September and early October 2026, attackers breached at least seven South Korean financial firms. Korea Herald-reported figures count roughly 66,000 individuals' records plus 2,200 corporate records. CrowdStrike Intelligence attributed the tooling to ARTEX, a free open-source agentic penetration-testing tool, with DeepSeek V4.1-Flash as the primary LLM backend.
Did AI hack the banks by itself?
No. South Korea's Financial Security Institute told Herald Business that AI was used as a tool by a human hacker and did not act independently. CrowdStrike's report describes ARTEX and LLMs working alongside traditional offensive tradecraft, including proxy infrastructure and manually run Claude Code sessions.
What LLMs did the ARTEX attacker use?
Per CrowdStrike's infrastructure analysis, the ARTEX instance used DeepSeek V4.1-Flash as its primary LLM backend, likely accessed through the API proxy or reseller xcai[.]pro, supplemented by GLM-5.3 (Zhipu AI) and Grok 4.6 for additional Claude Code sessions.
Is the ARTEX repository still available?
The original GitHub repository (Autumn-27/ARTEX) returned a 404 when we checked on October 9, 2026, while an English-UI fork (hongvincent/ARTEX) remained live. We make no claim about why the original repo is unavailable or whether it will return.
Who is behind the attacks?
CrowdStrike assesses with moderate confidence that the actor is a financially motivated Chinese speaker, based on the Chinese-developed tool and observed Chinese-language prompts. Resume details recovered from Claude Code sessions likely belong to the attacker but cannot be definitively confirmed. Korean police have a 28-member task force on the case.

Sources

  1. Unknown Threat Actor Uses AI-Driven ARTEX to Target South Korean Finance — CrowdStrike Intelligence
  2. South Korean officials believe AI agents were used to hack several banks — The Record
  3. South Korea Suspects AI Tool Helped Steal Bank Customer Data — GovInfoSecurity
  4. X post amplifying the CrowdStrike ARTEX report — X
  5. Bloomberg: Hacker who hit Korean banks likely from China, CrowdStrike says — Bloomberg
  6. Suspect behind South Korea bank hacks may be 26-year-old China cybersecurity worker — Reuters

About DeAI

DeAI is an independent publication covering open-weight AI models, private inference, and decentralized infrastructure — the tools for running AI you actually control. We test providers on price, privacy, and refusal behavior and publish the numbers, not the vibes. DeAI is powered by Morpheus (mor.org), a decentralized inference marketplace, and covers it on the same terms as every other provider.

Powered by Morpheus and StrandCMS

Morpheus is a decentralized inference marketplace, covered on the same terms as every other provider — we rank it wherever the data lands. StrandCMS is the open-source, agent-first framework this site is built on.

Learn more about the Morpheus Inference API →

Sponsor disclosure — not editorial

Powered by Morpheus and StrandCMS. Morpheus is a decentralized inference marketplace, covered on the same terms as every other provider. StrandCMS is the open-source, agent-first framework this site is built on.

Learn more →