Back to feed
News Story
APriority74
Import AI
1 sources

Self-Sustaining AI Virus Prototype Emerges: Uses Open-Weight LLMs to Spread

Researchers from multiple universities and institutions have built a prototype computer virus that uses open-weight large language models to compromise computers and leverage their GPU resources for inference, enabling it to intelligently spread to more hosts. This proof-of-concept demonstrates that self-sustaining AI-driven cyber threats are no longer theoretical, and preparations are needed for such threats.

SynthePulse Insight · AI deep reading

Autonomous Generative AI Worms: From Theory to Reality, and How Humanity Responds

Version 1 · 1 source

Researchers from the University of Toronto, Vector Institute, University of Cambridge, and ServiceNow have built a prototype AI worm that leverages open-source large language models to autonomously reason, discover vulnerabilities, and self-replicate on infected GPUs. This groundbreaking research marks that autonomous generative AI cyber threats are no longer theoretical, while also sparking urgent discussions about the pace of AI development and governance.

  • Researchers have built the first self-sufficient AI worm prototype, using open-source LLMs to run inference on infected GPUs, enabling autonomous attacks and self-replication.
  • The worm's success rates for vulnerability detection, exploitation, and self-replication are approximately 80%, 53%, and 88%, respectively, with a full attack success rate of about 37%.
  • The worm employs a decentralized swarm architecture with no single point of control, making it difficult to disrupt, demonstrating how AI agents might survive in future networked ecosystems.
  • Over 1,300 AI practitioners have signed a statement urging the U.S. government to support international cooperation to 'prudently advance the frontier of automated AI development.'
  • Dwarkesh Patel predicts that as AI systems become smarter, compute prices may rise significantly, for example, H100 rental could reach $250,000 per year.
Open section navigationAI Worm Prototype: A Self-Sufficient Autonomous Threat

AI Worm Prototype: A Self-Sufficient Autonomous Threat

Researchers from the University of Toronto, Vector Institute, University of Cambridge, and ServiceNow have built a prototype computer virus that uses AI models to compromise computers and leverages the GPU resources of infected machines for inference, thereby intelligently infecting more hosts. The research team states that this achievement 'proves that self-sufficient AI-driven cyber threats are no longer theoretical.'

The worm uses an open-source weights large language model (LLM) running on a single local GPU, without relying on any vendor APIs that could be monitored or revoked. The researchers did not disclose the specific model, only stating that it was released in 2025 and can fit on a single 80GB A100 GPU.

The worm implements functions such as network discovery, host discovery, vulnerability exploitation, privilege escalation, and self-replication through a custom toolkit. Its reasoning process is controlled by a 'directed graph' containing multiple specialized nodes, such as 'plan', 'judge', 'act', 'summarize', and 'progress', each focusing only on tools and prompts relevant to its role, thereby limiting context growth and avoiding confusion.

Success Rates and Decentralized Architecture: Why It Warrants Concern

The worm's success rates for vulnerability detection, exploitation, and self-replication are approximately 80%, 53%, and 88%, respectively, with a full attack success rate of about 37%. The researchers believe this figure is both concerning enough and makes it a useful benchmark for future testing of open-source models.

The worm employs a decentralized swarm architecture, with multiple independent copies running concurrently. Even if some hosts resist the attack, other copies continuously attempt new reasoning paths until success. The researchers emphasize that 'the worm is fully decentralized, with no single point of control that can be shut down to interrupt its spread.'

This research reveals that the future internet may evolve into a complex ecosystem of offensive and defensive AI agents. The researchers suggest that humans may need to create their own AI agents as 'white blood cells' to counter malicious models.

AI Development Pace and Governance Calls

Meanwhile, a statement signed by senior representatives from major AI labs including OpenAI, Anthropic, Google DeepMind, Thinking Machines, Meta, and Safe Superintelligence Inc. urges the U.S. government to support international cooperation to 'develop the necessary technical and governance tools to prudently advance the frontier of automated AI development.' Signatories include chief scientists and co-founders from Anthropic, Google, and OpenAI, as well as CEOs of Safe Superintelligence and Anthropic.

The statement notes that leading AI companies may be approaching automated AI research, which could lead to rapid acceleration in capability development, outpacing human understanding and control. The statement emphasizes that industry, government, and society may need to 'buy time' to address emerging risks, develop safety measures, and strengthen oversight, but every company and country faces intense competitive pressure and is reluctant to unilaterally slow this process.

The Economics of Compute Costs: Intelligence Gains and Price Surges

Dwarkesh Patel suggests that as AI systems become smarter, compute prices may rise further. He argues that if an AI software engineer could run on H100-equivalent hardware, the annual rental for that H100 should exceed $250,000, 15 times the current spot price, based on the market price of a software engineer.

Patel explains that AI is currently relatively cheap partly because it cannot do many things that top humans can, but once that changes, applications like using GPUs to make low-quality short videos will be priced out. He expects this price increase to be temporary, as large-scale robotization of the compute supply chain could eventually bring prices back close to the cost of raw materials and tools, but by then we may be deep into the 'singularity.'

Credibility boundary

This report is based on a secondary account from Import AI; the original research paper (arXiv) and the statement text were not directly provided. All specific figures and conclusions come from Import AI's account and have not been independently verified from primary sources, so they are marked as source claims rather than confirmed facts.

Insight takeaway

The successful demonstration of an autonomous AI worm shows that AI-driven cyber threats have moved from theory to reality, and its decentralized architecture and self-sufficiency pose serious challenges to existing defense systems. Meanwhile, concerns within the AI community about the pace of development are growing, prompting calls for international governance cooperation, while changes in the economics of compute costs may further reshape the AI landscape.

Primary report

Import AI

Primary source