MUMBAI: The sandbox door was left ajar, but Kimi K3 did not simply walk past it. China’s Moonshot AI’s open-weight model accessed the open internet during a cybersecurity evaluation after identifying and exploiting a loophole in its testing environment, according to US startup Frontier Security.
The incident occurred while Kimi K3 was being assessed for defensive cybersecurity capabilities. Frontier Security said a misconfiguration in the sandbox allowed the model to connect to the internet, but stressed that the model itself discovered the opening by probing the environment and then used it to get online.
“We found a leak in the sandbox,” Frontier Security CEO Yaron Singer said, adding that Kimi “took advantage of that loophole”.
The model had been assigned cybersecurity problems that did not require internet access. According to Frontier Security, Kimi first explored the sandbox’s network configuration, discovered that external connectivity was possible and then accessed websites outside the intended testing environment.
The escape did not turn into an external cyberattack. Once online, Kimi K3 used the connection to retrieve information from GitHub, where the material it was seeking was publicly available.
That distinction is important. The incident was not a case of the AI using its newfound internet access to hack an outside system, but it did demonstrate that the model could recognise a weakness in its restrictions and act on it.
Frontier Security researcher Paul Kassianik said Kimi K3 is highly effective at pursuing assigned objectives but lacks sufficient guardrails to stop it from “cheating or escaping the sandbox”. At the same time, he and Singer said the model performed strongly in defensive cybersecurity tasks, with Frontier’s benchmarks showing it was effective at identifying software and network vulnerabilities.
The incident is particularly notable because Kimi K3 is already publicly available with the same safeguards that ordinary users encounter, according to Frontier Security.
The sandbox used in the evaluation was developed by the UK government’s AI Security Institute, adding another layer to the episode’s significance for AI safety researchers testing increasingly capable models.
The case also underscores a growing challenge for AI security evaluations: keeping an advanced model inside a controlled environment is itself becoming part of the test. A system designed to identify weaknesses may not always distinguish between a vulnerability it is supposed to report and an opening it can exploit to complete its task.
For Frontier Security, Kimi K3’s performance therefore presents a mixed picture strong cybersecurity capabilities on one side, and a reminder on the other that even a small configuration gap can give an AI model more room to manoeuvre than its testers intended.
