ACVEAgent configuration vulnerability registry

ACVE-2026-0551

Three open-source attack agents run by one operator stole at least 600,000 card details and planted skimmers on retailer sites; one agent also dropped 180 tables, backups included.

Exposure

Reproducibility: partial (model availability not checked (no registry reference); trigger not published)

Claims

Confirmed means the statement matches the cited primary source. Nothing on this page has been reproduced.

The exposure axes marked confirmed were matched to the first-hand sources listed above.

Description

Threat

user · unsafe-default · exfiltration

What

Gambit Security's interim report says an operator ran three open-source AI harnesses through almost the entire attack chain against online retailers: Strix for vulnerability search, Cairn for autonomous exploitation and Hermes to orchestrate, with 1,951 human prompts across 260 sessions, only a few per target. Hermes used Anthropic's Opus 4.6 after newer models refused its requests; Strix ran on GLM 5.2 and later DeepSeek v4 Pro, and Cairn on DeepSeek v4.1 Flash, with model access through OpenRouter. One of the operator's main objectives was injecting card-stealing skimmers into checkout pages. Gambit counts at least 600,000 unexpired card details stolen from two companies, skimmers ordered against at least 27 named victims and confirmed on 19, and more than 100 further websites carrying a skimmer associated with the campaign. Data loss came two ways: an operator-written skill wiped card fields after extraction, and an agent matching table names too broadly dropped 180 tables at one retailer, including backup tables its administrators had made.

Detection

Gambit bases its account on the attacker's staging server, live skimmers and the attacker-side logs, and warns that a few errors are possible. Recorded from Gambit's report and its researcher's posts on X. Not recreated in a lab.

Fix

Separate data access from cleanup, require review for retailer changes, and keep cardholder data outside unattended agent reach.

Fix

The operator ran the attack, so victims depend on Anthropic and OpenRouter cutting off the harnesses and on backups kept outside the production database.

  • Reconfigure anthropic.opus-4-6 to refuses the requests newer models refused. Recommended: Hermes switched to Opus 4.6 after newer models refused its requests. Owner: model-provider
  • Reconfigure openrouter.accounts to detects and cuts off accounts driving attack harnesses. Recommended: all three harnesses reached their models through OpenRouter. Owner: model-provider
  • Reconfigure database.backups to kept outside the production database. One agent dropped 180 of the targeted organisation's tables, its backup tables among them. Owner: operator

References

ARTICLE

Report a problemJSON