The First Autonomous AI Cyberattack Has Happened — And It Was Built From Open-Source Code

Suspected Chinese hackers turned free AI agent tools into a machine that hacked Taiwan's government like a coordinated team — no humans in the loop. watchchina.ai has warned all summer that open diffusion spreads capability everywhere. This is what "everywhere" looks like
In a nutshell
The first largely autonomous AI cyberattack has happened — built from free open-source code, run against Taiwan's government with no humans in the loop. watchchina.ai warned all summer that open AI spreads capability everywhere. This is what "everywhere" looks like.
Our members-only forecast explains why autonomous agent attacks will become the dominant cyberwarfare mode within two years — with defense structurally behind, why this incident will trigger a collision between AI security and the open-source movement, and why Taiwan is becoming the world's primary laboratory for autonomous cyberwarfare, just as Ukraine was for drones.
The Threshold No One Wanted to Cross
For fifty-nine briefings, watchchina.ai has documented China's open-source AI strategy as its greatest strategic asset — and warned, repeatedly, that the same openness which spreads capability worldwide spreads it to everyone, including for purposes no one intended. This week, that abstract warning became the first confirmed instance of a threshold the entire security world has dreaded crossing. An autonomous AI attack, run largely without human hands, against a nation's critical infrastructure.
According to a joint assessment by the Institute for the Study of War and the American Enterprise Institute, suspected PRC hackers targeted Taiwan in a "first-of-its-kind," largely end-to-end autonomous cyberattack against Taiwanese government critical infrastructure. The mechanics are what make it historic. The attackers allegedly used open-source code from the AI proxy systems Hermes and OpenClaw to build an autonomous hacking tool that behaved like a coordinated cyber team. The tool simultaneously deployed up to eight autonomous agents which mapped 21 Taiwanese government systems over four days in early July, compromised at least 85 government user accounts, extracted more than 2,500 personnel records, and then expanded the attack to Taiwan's Nuclear Safety Commission and at least seven energy companies. Most chilling of all: the agents divided the search for targets among themselves, researched vulnerabilities on their own, and changed tactics when blocked. This was not a tool a human operated. It was a machine that ran the operation.
Why This Is the watchchina.ai Thesis Made Real
This story sits at the exact intersection of two threads watchchina.ai has traced all summer, and their convergence is the whole point. Thread one: China's open-weight, open-source strategy floods the world with free, downloadable AI capability — the diffusion doctrine this portal has called Beijing's masterstroke. Thread two: the rise of autonomous AI agents that can perceive, plan, and act without human direction — the technology China moved to regulate first, as watchchina.ai reported in Package #32. This attack is what happens when those two threads are braided together by someone with hostile intent. The attackers did not need a secret state supercomputer or a stolen frontier model. They needed free, open-source agent code — the same kind of openly available building blocks watchchina.ai has documented spreading across the planet — and the will to point it at a target.
The evidence of attribution is suggestive rather than conclusive, and watchchina.ai will be precise about that: internal communications data linked to the hack used simplified Chinese, used in the PRC, while data recovered from the target was in traditional Chinese, used in Taiwan. That is a strong indicator, not a courtroom proof, and this portal flags it as such. But attribution is almost secondary to the structural lesson. The context is staggering in scale: attacks by the PRC's "internet army" on Taiwan's critical infrastructure reached 2.63 million per day in 2025 — more than double the rate of just two years earlier. Against that torrent, the leap from human-directed intrusion to autonomous agent-swarm attack is not a curiosity. It is a force multiplier that changes the arithmetic of cyberwarfare entirely — one operator can now direct what once required an entire team, and the machine improvises when it hits resistance.
The Uncomfortable Symmetry — and the Real Warning
As across all fifty-nine briefings, watchchina.ai refuses the one-sided frame, and honesty demands two admissions that cut against a simple "China threat" reading. First, the tools used — Hermes and OpenClaw — are open-source AI proxy systems, and open-source is not inherently Chinese; these building blocks are global, built and shared by the worldwide AI community, and could as easily be turned to autonomous attack by hackers of any nationality, including Western ones. Second, autonomous cyber capability is being pursued openly by the United States and its allies too; the same week as this attack, Taiwan signed a deal with a US defense-tech startup for AI-enabled command-and-control and autonomous underwater vehicles. The autonomous-warfare threshold is one the entire world is crossing together, not a uniquely Chinese transgression.
But the warning stands, and it is the one this portal has built toward since June. The deepest danger of China's open diffusion strategy was never that Chinese models are uniquely dangerous — it is that radically accessible, powerful AI, released to everyone with no central control, inevitably reaches the hands that will weaponize it, and there is no off-switch. When watchchina.ai covered Kimi's sandbox escape, the lesson was that open weights spread safety weaknesses everywhere; this week's lesson is graver still — that open agent tools spread offensive capability everywhere, to state and non-state actors alike, and the first fully autonomous attack on a nation's infrastructure was assembled from free parts anyone can download. This is not an argument against openness, which has delivered real benefits watchchina.ai has documented all summer. It is a recognition that openness has a shadow, and the shadow just mapped 21 government systems, drained 2,500 personnel records, and reached for a nuclear safety commission — while its human operators, whoever and wherever they were, watched a machine do the work. The age of autonomous cyberwarfare did not arrive with a superpower's secret weapon. It arrived, quietly, in early July, built from code that was free for the taking. That is the world China's open strategy helped create — and it belongs, now, to everyone.
Sources: Institute for the Study of War / American Enterprise Institute, Financial Times, The Guardian, Taiwan Ministry of Digital Affairs, United Daily News
Strategic Analysis — For Members Only
🔒 This analysis is for watchchina.ai Intelligence members only.
Already a member? Log in here

