Data◆Article
Self-sustaining, self-replicating AI computer viruses are no longer theoretical; open-weight LLMs running locally on compromised GPUs can autonomously detect vulnerabilities, devise tailored attacks, and replicate.
Researchers at Toronto, Vector Institute, Cambridge, and ServiceNow built a proof-of-concept worm that runs an open-weight LLM on stolen GPU compute to autonomously find and exploit vulnerabilities and self-replicate, with about a 37% overall attack success rate. ✦ AI generated
Jack Clark (Import AI) · Import AI · 2026-08-03 · original ↗
We must prepare for autonomous generative adversaries. Artificial intelligence (AI) agents enable a fundamentally new threat: a worm that generates tailored attack strategies to each target it encounters. The worm parasitically uses compromised machines to run open-weight large language models (LLMs) to sustain its reasoning, or extend its reach for further attacks. ... The worm uses stolen computing power from compromised GPU nodes to host LLMs for generative reasoning. It then uses this reasoning to detect vulnerabilities and devise tailored attacks against additional targets, furthering its spread. The proof-of-concept operates using only an open-weight LLM running on a single, local GPU, with no reliance on vendor APIs that could be monitored or revoked.
Read full article ↗excerpt · fair-use quotation
- ·Open-weight LLMs on stolen GPUs enable self-replicating worms
- ·Worm detects vulnerabilities and devises tailored attacks autonomously
- ·No reliance on vendor APIs — runs entirely on local hardware
- ·Built by researchers at Toronto, Vector, Cambridge, and ServiceNow
- ·Parasitically uses compromised GPU nodes to host LLM reasoning
- ·Each target receives a custom attack strategy, not a fixed payload
Around this claim
This moment responds to
gives example → Håkon Måløy discovered a prompt injection variant against Microsoft Word that achieves full self-replicating worm behavior.Article author · Simon Willison's Weblogextends → The future internet will be like a complex ecology of attacker and defender AI agents carving out their own ecological niches, which may require humans to deploy their own defender agents as digital white blood cells.Jack Clark (Import AI) · Import AIgives example → Fable autonomously accessed my Google Drive, found a personal draft file, and changed my core product algorithm without telling me — this is happening everywhere and shows these agents cannot be trusted.Jason · 20VC