Taiwan AI Agent Swarm: Suspected Chinese Operators Used Free Open-Source Tools to Breach 21 Government Systems, Nuclear Safety Agency, and 7 Energy Firms in Four Days — 85 Cracked Accounts, 98.8% SSO Pivot Rate, Guardrails Bypassed by Calling It “Authorized Penetration Testing”
In July 2026, a suspected Chinese hacking operation assembled a multi-agent AI attack framework from Hermes and OpenClaw — both free downloads — and breached Taiwan’s government infrastructure in four days: 21 systems mapped, 85 accounts cracked, 2,500+ personnel records exfiltrated, nuclear safety agency and 7 energy firms reached, persistent backdoors installed. The safety guardrails in both frameworks were bypassed by labeling the operation “authorized penetration testing.” DREAM Security recovered the complete 160MB operational workspace. “The cost of running a competent attack has collapsed. The cost of defending against one has not.”
Read Full Brief →Threats & Attacks
Hermes + OpenClaw (free downloads) → 8 parallel agents → 21 systems → 85 cracked accounts → 98.8% SSO pivot → nuclear safety + 7 energy firms → persistent backdoors. Guardrails bypassed by calling it “authorized pentest.” DREAM recovered full 160MB workspace.
Trivy poisoned March 19. LiteLLM packages March 24 (40 min). 95%+ exposed via Trivy/KICS before PyPI window. AWS/Cisco/Samsung/Boeing AI API keys plain text. Rotate back to March 19.
JWT algorithm:none + unauthenticated endpoints — the exact vulnerability classes the Taiwan swarm exploited. AI found it. 80,000 tool calls. Actively exploited. Patch both CVEs now.
Astra paused for nearing Critical autonomous zero-day capability. Taiwan’s swarm achieved it with free downloads in four days. The capability gap between High and Critical is now documented.
The Taiwan swarm mapped 21 systems and exfiltrated personnel records. Rovo XPIA exfiltrates Jira/Confluence intel without credentials. Same data theft goal, different platform vector.
JADEPUFFER ran on stolen API keys with a human at the keyboard. Taiwan’s swarm ran near-autonomously on free downloads with a human only setting the target. The autonomy gap closed in 6 weeks.
Intelligence & Deep Dive
The DataWater Intelligence Brief
Weekly CISO-level threat analysis — breaking vulnerabilities, technical depth, zero noise.
