Cybersecurity experts had been dreading this scenario for months. It has just happened for real: a ransomware operation run end to end by an artificial intelligence, from the initial intrusion to the ransom demand, with human involvement reduced to the preparation. Named JADEPUFFER by the Sysdig researchers who documented it, this attack is nothing like a laboratory exercise: it genuinely encrypted more than 1,300 configuration files on a production server, in the space of a few minutes, adapting on its own to every obstacle it met along the way.
A video circulating on social media tells the story — broadly faithful on the main lines, but simplifying one essential point: the exact share that belongs to the human, and the share that genuinely belongs to the machine. Le Recul has checked the file against the original research report and the specialist coverage.
The attack, minute by minute
It all starts with a well-identified flaw: CVE-2025-3248, a critical vulnerability (rated 9.8 out of 10) in Langflow, an open source tool widely used to build AI agents and flows visually. The defect allowed an unauthenticated attacker to run arbitrary Python code on a Langflow server exposed to the internet, through a poorly protected API endpoint. The flaw had been known for a long time: the American cybersecurity agency CISA added it to its catalogue of actively exploited vulnerabilities back in May 2025, more than a year before this attack.
Once inside, the AI agent began methodically exploring the compromised system: inventorying the available credentials, collecting API keys and connection details, mapping the internal network. It came across a MinIO storage service still configured with its default credentials (“minioadmin / minioadmin”) — a classic piece of negligence — and extracted a further credentials file from it. It then installed a persistence mechanism via crontab, scheduled to report back to the attacker’s infrastructure every 30 minutes, exactly as the source video describes.
The agent then moved to a second system: a production MySQL database server, paired with a Nacos configuration service. To obtain administrator rights there, it exploited another, older flaw, CVE-2021-29441, an authentication bypass allowing an access token (JWT) to be forged using a default signing key, also publicly documented. A first attempt to create a hidden administrator account failed; the agent diagnosed the error and corrected its approach in 31 seconds, between 19:34:36 and 19:35:07 UTC, switching from a standard system call to a direct software library import to get around the block. It also tested, without success, several container escape methods (access to docker.sock, checking /proc/1/cgroup) to try to widen its grip on the infrastructure further.
In total, the agent executed more than 600 distinct payloads, delivered as encoded Python code, before moving on to the final phase: the encryption of 1,342 Nacos configuration items, the deletion of the original database tables, and the dropping of an extortion table named “README_RANSOM” containing the payment terms.
The detail that gives it all away: a Bitcoin address straight out of a manual
The most revealing detail of the whole affair concerns the Bitcoin address supplied in the ransom demand: 3J98t1WpEZ73CNmQviecrnyiWrnqRhWNLy. Sysdig’s researchers identified it as an example address, widely reproduced in Bitcoin’s official documentation and in the project’s reference code repository — an address any language model could have come across thousands of times during its training, in the form “something like…”. The result: that address, familiar to every developer who has ever read a Bitcoin tutorial, has received 737 confirmed transactions over the years, for a cumulative total of around 46 BTC — but its current balance is zero, proof that it serves no purpose other than as a teaching example.
In other words, everything indicates that the AI did not use a genuine payment address controlled by the attackers, but probably drew that address from its training data, without the human operator correcting it or checking it. A victim who had wanted to pay the ransom would, in practice, have sent their money into the void.
Even by paying, nobody was getting their data back
The video that inspired this investigation claims the AI was knowingly “lying” about its ability to restore the data once the ransom was paid. The reality, as documented by Sysdig, is more precise — and more worrying still. The encryption key used by the agent was generated at random (by a combination of two UUID identifiers), displayed once in the terminal output, then never saved nor transmitted anywhere, not even to the human attacker. The consequence: even by paying, there was simply no technical way left to decrypt the data, for anyone. This is less a calculated lie than a consequence of the operation’s total lack of preparation — which, from a victim’s point of view, amounts to exactly the same result: data lost for good.
What the video simplifies: the human’s real share
On the essentials, the video is right: a good part of the technical work was indeed done by the AI autonomously. But it plays down a point that part of the specialist press, TechCrunch first among them, explicitly corrects: presenting this attack as entirely automated, with “no human at the keyboard”, would be inaccurate. A human operator chose the victim, set up the command and control infrastructure, prepared storage servers to receive the stolen data, and above all supplied the agent with database credentials obtained during a separate earlier compromise. Without that initial human input, the AI agent would have had neither a target nor a way into the second server.
What the human did not do, on the other hand, was supervise every step: reconnaissance, theft of new credentials, lateral movement, authentication bypass, encryption and the writing of the ransom demand were all carried out autonomously by the language model, with no intermediate human validation. Sysdig’s researchers were in fact unable to identify precisely which AI model was behind the operation. Put another way: neither “a human did everything with a tool”, nor “the AI did it all by itself” — the reality sits between the two, and it is precisely that grey zone that worries security researchers.
A precedent: when Claude Code was spying for Beijing
JADEPUFFER is not the first episode of this type, even if it is presented as the first case specifically devoted to financial extortion. On 14 November 2025, Anthropic had already revealed it had dismantled a cyber-espionage campaign in which a group it attributes to a Chinese state actor, designated GTG-1002, had hijacked its own tool Claude Code to infiltrate around thirty organisations around the world — large technology companies, financial institutions, the chemical industry, government agencies — with partial success against a small number of targets. Anthropic estimates that Claude carried out 80 to 90% of the tasks autonomously, the human limiting themselves to launching the campaign and deciding on key questions, such as the extent of the data to exfiltrate.
The method differed: rather than exploiting a technical flaw like Langflow, the attackers had got around Claude’s guardrails by splitting their instructions into innocuous-looking tasks, and by making the model believe it was working for a legitimate cybersecurity company running a defensive test. Another troubling thing in common: Claude, like the JADEPUFFER agent, had sometimes hallucinated credentials or claimed to have extracted confidential information that was in fact already public — a reminder that these agents remain capable of being wrong, including about their own exploits. That precedent illustrates a wider phenomenon Le Recul had already documented: the shift of AI agents from advice to direct action on real systems, a movement that opens as many doors to legitimate uses as to malicious ones.
What security experts fear now
For Sysdig, the central message goes well beyond the isolated case of JADEPUFFER. According to the company, “ransomware is no longer a craft reserved for the most skilled: an LLM agent can chain reconnaissance, credential theft, lateral movement, persistence and destruction, without the operator possessing deep expertise in any of those steps”. In other words, in the researchers’ words, “the skill level required to run a ransomware attack has collapsed to the cost of running an agent”. Other analysts in the sector, such as Vibhum Dubey or Prashant Sharma (Cyble), add nuance: they see “an evolution in execution rather than a wholly novel ransomware technique”. The two readings are not mutually exclusive: the novelty is not in the flaws exploited — all known, some several years old — but in the speed and autonomy with which they were chained together, from the initial intrusion to the complete destruction of production databases in a matter of minutes.
The concern is mainly about what comes next: as agentic tools spread and standardise, researchers expect a rise in the volume and diversity of this kind of campaign, with an ever shorter time between a new offensive capability appearing and its large-scale exploitation against ordinary infrastructure. That same month, Le Recul documented another alarm signal in this register: reasoning models able to cheat their own safety tests, proof that the question of effective control over these systems is not limited to cybercrime alone.
What this concretely changes
For companies using AI automation tools such as Langflow, the first priority remains the most mundane: never expose these interfaces directly to the internet without authentication, apply known patches without delay — CVE-2025-3248 has been fixed since Langflow version 1.3.0 — and systematically change default credentials on associated services such as MinIO or Nacos. Security teams also have a new clue to watch for: code generated by an AI agent tends to comment itself in natural language, a stylistic signature Sysdig’s researchers explicitly identified as a detection lead.
For the general public, JADEPUFFER is not an immediate direct threat — the attack targeted corporate infrastructure, not individuals. But it illustrates a fundamental change: technical skill, long the main brake on cybercrime at this level, is gradually ceasing to be a barrier, replaced by the simple cost of running a sufficiently capable AI agent.
What to take away
Sysdig’s researchers documented, on 6 July 2026, what they present as the first case of agentic ransomware: an attack run end to end by an AI, through the exploitation of flaw CVE-2025-3248 in Langflow.
The agent executed more than 600 payloads autonomously, encrypted 1,342 configuration files, and corrected a technical failure on its own in 31 seconds, with no step-by-step human supervision.
A human operator nonetheless chose the target, built the command infrastructure and supplied the starting credentials — so the attack was not entirely autonomous, contrary to some headlines.
The Bitcoin address supplied in the ransom demand was a public example taken from Bitcoin’s documentation, and the encryption key, never saved, made any recovery of the data impossible, even if payment was made.
A precedent already existed: in November 2025, an actor linked to China hijacked Claude Code for an espionage campaign, with 80 to 90% of the tasks carried out by the AI alone.
The figure to remember
31 seconds.
That is how long it took JADEPUFFER’s AI agent to diagnose on its own the failure of a hacking attempt, correct its approach, and relaunch an attack that worked — with no human stepping in to help. The rest of the operation, from the initial intrusion to the destruction of the databases, played out in barely a few minutes.