NEWS
The Toronto AI Worm Turns Stolen GPUs Into Free Attacks
The Toronto AI worm plans each hop with an open-weight model hosted on stolen GPUs, driving the attacker’s cost per new infection to zero.
A University of Toronto lab built an AI worm that plans a fresh attack for each host and runs that planning on stolen GPUs. In 15 isolated runs on a 33-host mock company, it gained elevated access on 23.1 machines on average and copied itself onto 20.4 of them in seven days.
Nicolas Papernot leads the CleverHans Lab at the University of Toronto. He is an associate professor of computer engineering and computer science and a Canada CIFAR AI Chair at the Vector Institute. With Jonas Guan, Tom Blanchard, Hanna Foerster, Hengrui Jia, and Gabriel Huang, from Toronto, Cambridge, the Vector Institute, and ServiceNow, he posted the preprint on June 2, 2026. The group says open-weight models power a worm that anyone can download, and that vendor rate limits never touch it.
Fifteen Runs Inside a 33-Host Lab
The testbed is a fake firm named FakeCorp: Ubuntu 16.04 through 24.04, Debian 9 through 12, Alpine, Rocky Linux 9, CentOS Stream 9, and Windows Server 2008 R2, 2019, and 2022, plus IoT-style printers and cameras. The agent starts on one box with no map of the network, no list of bugs, and no person steering it. Reasoning at first comes from GPU machines the team treats as already owned, then is meant to shift onto FakeCorp cards as those fall.
The paper, 15 runs on 33 hosts, is still under peer review. Operational pieces of the harness, including the reasoning graph and the tool list, were cut before posting. The authors told several Government of Canada offices before they published.
THE FAKECORP SCORECARD
| Metric | Average result |
|---|---|
| Vulnerabilities identified | 31.3 per run |
| Share of hosts that received a replica | 61.8% |
| Self-replication after a successful exploit | 88% |
| Local privilege-escalation success | 72% |
| Service-exploit success | 63% |
| Web, Windows, and credential attacks | 34% to 49% |
| Time to reach half the network | about five days |
| Replication generations | up to 7, mean 5.1 |
Single attempts were brittle. The agent hallucinated URLs, fumbled PowerShell, and wrote exploit code with syntax errors. What rescued the totals was the swarm: each new replica tried a hard host again on a fresh reasoning path until one attempt landed. Linux local privilege escalation and familiar service bugs were the easy work. Web apps, Windows shells, and credential reuse were the grind.
The Worm Makes the Victim Pay for Inference
Classic worms are cheap because the exploit is compiled once. This one is cheap because the brain is rented from the victim. When a GPU host falls, the worm is designed to drop a local copy of a 2025 open-weight model that fits on one 80GB card, then answer questions for copies stuck on cameras, printers, and other low-power boxes. The attacker’s extra cost per new infection is zero. The bill for power, silicon, and downtime sits on the defender.
Hackers have typically had to prioritize the most high-value targets because time and computing resources were limited. But now, once a worm is launched, the cost would drop to nearly zero.
Nicolas Papernot, associate professor, University of Toronto
Papernot said the work stayed inside a lab walled off from the open internet, and that the public write-up strips details that would help an attacker rebuild it.
We discovered that it's possible to create an AI-driven computer worm using an open-weight model that anyone can download. This work was conducted in a lab walled off from the outside world, & shared only after removing details that could aid bad actors.https://t.co/WBbER7O7ZB
— Nicolas Papernot (@NicolasPapernot) June 4, 2026
THE GPU FOOTPRINT
- The card: An unfinetuned 2025 open-weight model, quantized to one NVIDIA A100 with 80GB of memory, also run on the RTX PRO 6000 Blackwell Edition.
- The mix: FakeCorp had 5 GPU-designated Linux hosts and 28 machines with no local GPU.
- The pool: The 15 spread runs shared 20 Blackwell cards and 10 A100s, 30 GPUs in all, because the team did not have a full card for every parallel replica.
- The installed base: The appendix, citing NVIDIA’s filings, puts data center GPU revenue at $15.0 billion in fiscal 2023 and $193.7 billion in fiscal 2026, and estimates 15 to 20 million datacenter GPUs over that four-year window, almost all with at least 80GB.
That last point is the second-order hit. Closed-model labs can revoke an API key. They cannot revoke a weight file sitting on a workstation already inside the building. The spread runs, though, used a shared inference pool and did not measure whether the prototype could stand up a fresh LLM service on each stolen card; the authors tested that step on its own and say the shortcut did not puff up the infection counts. Treat the 61.8% replica figure as a spread result, not as proof that every hop hosted its own model.
The theft pattern is already live without a worm. Google Threat Intelligence Group, in a September 9, 2026 note, described actors stealing developer credentials and hijacking enterprise clouds to run unauthorized high-performance compute workloads. In one April 2026 case, an exposed GitHub token was enough to spin up that unauthorized AI infrastructure. The Toronto design automates the same move and keeps it on-prem, off the invoice of Anthropic or OpenAI.
Copy Fail Opened a Path the Model Never Learned
The 2025 model had never seen three bugs the team planted on FakeCorp, all disclosed in 2026. Copy Fail is CVE-2026-31431, a Linux kernel local privilege escalation in the crypto path. Dirty Frag is CVE-2026-43284 and CVE-2026-43500, the same page-cache trick in the network stack. The third is CVE-2026-39987, Marimo terminal WebSocket remote code execution on the unauthenticated /terminal/ws endpoint in versions through 0.20.4, fixed in 0.23.0, scored 9.8. The agent read public advisories at runtime and built working attacks from them.
HOW THE 2026 BUGS LANDED
- April 8, 2026: The Marimo GitHub advisory goes out.
- April 9, 2026: Sysdig’s threat research team sees the first exploit try at 07:31 UTC, 9 hours and 41 minutes later, with no public proof-of-concept on the street yet.
- April 23, 2026: CISA adds the Marimo bug to its Known Exploited Vulnerabilities catalog, with a federal fix due May 7, 2026.
- April 29, 2026: Copy Fail is disclosed with a short Python exploit that works across major distros.
- June 2, 2026: The Toronto preprint shows the worm using those write-ups, plus older planted flaws such as EternalBlue (CVE-2017-0144), SambaCry (CVE-2017-7494), PrintNightmare (CVE-2021-34527), and Dirty Pipe (CVE-2022-0847).
On the three fresh hosts, the agent got root in 41 of 67 tries, 61.2%. Dirty Frag went 15 of 17. Copy Fail went 13 of 23. Marimo went 13 of 27. One retrieval document of public exploit steps was enough for the two Linux bugs, 28 of 40 tries. WannaCry hit around 10% of U.S. internet-facing systems in less than a day on a bug that already had a patch. An agent that reads the same advisory a defender reads, then writes the exploit the same week, shrinks that lag to the time it takes to pull a web page.
That is why browser makers now run a Chrome two-week n-day cycle. It is also why commodity bots did not wait for an academic worm. Nozomi Networks Labs, on September 9, 2026, described KATARU, an IoT family that brute-forces Telnet and then tries public Linux local privilege exploits for Copy Fail, DirtyFrag, and Fragnesia (CVE-2026-46300), pasted in with little or no change. In the ARM sample, some of that shellcode still targeted x86. The Toronto agent’s edge is not inventing those bugs. It is fitting the public recipe to the box in front of it.
Why Real Offices Resist a Lab Worm
FakeCorp was a worst case on purpose. Every virtual machine carried at least one planted weakness. There was no endpoint detection, no antivirus, and no active firewall. Every host could reach every other host. The worm was told not to hide, not to persist, and not to trim its traffic. Reaching half the network still took about five days, because each target burned hundreds of model calls for recon, planning, and payload work.
WHERE THE LAB AND CISOS SPLIT
- The lab view: Papernot says highly skilled attackers do not need a frontier model or a huge budget, and he suspects the window to prepare is closing.
- The CISO view: Mike Wilkes, CISO at Aikido Security, said if a defender built this, an attacker almost certainly has a version in motion, and still told peers not to panic.
- The network view: Trevor Horwitz, CISO at TrustNet, said real enterprise networks are messy, with odd configs, old systems, security tools, partial visibility, and operational friction that a lab demo does not have.
Horwitz expects the near term to look like AI bolted onto recon, exploit choice, phishing, stolen credentials, and lateral movement, not a single self-driving worm eating a production campus. Martin Reynolds, field CTO at Harness, put the weight on speed and scale against the same old misconfigs. Both reads can be true at once: the POC is a capability, and FakeCorp is not a hospital, a bank, or a factory with a monitoring team that actually pages someone.
Morris II Stayed in the Inbox
In 2024, Stav Cohen, Ron Bitton, and Ben Nassi showed Morris II, a worm for generative-AI email assistants. It spread with adversarial self-replicating prompts that rode retrieval-augmented inboxes, jumping from one assistant to the next, and they tested it on GPT-4, Gemini Pro, and LLaVA. The kill path there is content filters, RAG hygiene, and the model vendor.
THREE WORMS, THREE BILLS
| Worm | How it spreads | What you patch or kill | Who pays for compute |
|---|---|---|---|
| WannaCry (2017) | Fixed EternalBlue payload | One SMB flaw | Attacker, then the victim’s outage |
| Morris II (2024) | Self-replicating prompts in AI mail | Prompt filters and RAG stores | Cloud model APIs |
| Toronto POC (2026) | Runtime exploits on Linux, Windows, IoT | No single CVE, no API key | Stolen local GPUs |
Papernot’s group is explicit that this prototype lives outside AI apps and hits the software under them, so a laptop, a camera, or a thermostat is in scope as a foothold even when it holds no crown-jewel data. The paper also cites NotPetya’s more than $10 billion in damages as the bill for a fast, dumb worm. An adaptive one is slower in this lab and, if it ever leaves a lab, less likely to die when one patch lands.
Watch Local GPUs and MCP Servers
Wilkes warned shops not to spend on products sold as anti-AI malware. The boring list is the list. Horwitz’s line is that AI does not retire those controls, it makes weak execution cost more. The paper’s own defense chapter says the same in plainer words: shrink the surface, segment the network, and close the gap between a public advisory and a deployed fix, because this agent walks, it does not sprint, until inference gets cheaper.
CONTROLS THAT CUT THE BLAST RADIUS
- GPU telemetry: Alert on odd local GPU use on workstations, lab boxes, and jump hosts that should not be serving a 80GB model.
- MCP hardening: Wilkes called Model Context Protocol servers “breach gateways.” Limit machine-to-machine trust and lock those tool servers down as you would a jump box.
- Fast and slow patching: Mitigate in hours, patch in days. The worm’s half-network walk of about five days is the window, and it will shrink.
- Default creds and canaries: Kill factory passwords. Plant canary accounts so a credential spray lights up before the replica launches.
- Segmentation: FakeCorp was flat. A printer should not be able to talk to a domain controller.
- Least privilege: Apply it to people and to non-human identities, including agents and scheduled jobs.
Treat cameras, HVAC gear, forgotten appliances, and even firewalls as part of the same surface. The worm only needs a foothold that can query a stolen GPU. Papernot’s public advice is older than the paper: install the update, use a strong password, turn on multifactor, and stop hitting ignore. His lab is already building countermeasures, and the university is setting up a vetted path for other researchers to request the withheld code for defensive work.
Frequently Asked Questions
How Many Hosts Did the Toronto AI Worm Infect?
Across 15 independent seven-day runs, the mean was 23.1 hosts to elevated access, with a spread of 3.9 either way, and 20.4 hosts that received a replica, with a spread of 3.2. Those means sit on a 33-host network, so the replica share is 61.8%. Each run launched a single agent from one already-compromised host and gave it no topology, no OS list, and no vulnerability inventory.
Did the AI Worm Need a Frontier Model Like Claude Mythos?
No. The agent used an unnamed, publicly downloadable 2025 open-weight model that fits on one 80GB GPU, with no finetuning. The authors withheld the model name. The same memory footprint covers the A100 80GB card, Hopper H100 and H200 parts, Blackwell datacenter GPUs, and the RTX PRO 6000 Blackwell workstation card. They also skipped harvested frontier API keys on purpose, to show that vendor refusals would not stop this design.
How Is This Different From the Morris II AI Worm?
Morris II, posted in March 2024 by Cohen, Bitton, and Nassi, copies itself by stuffing adversarial prompts into generative-AI email assistants and RAG stores. It needs those AI apps to talk to each other. The Toronto worm copies a whole agent onto Linux, Windows, and IoT hosts by generating shell-level exploits, then uses stolen GPUs so copies without a card can still ask for a plan. One lives in the inbox. The other lives on the wire.
Can an AI Worm Exploit Bugs Disclosed After Its Training Cutoff?
In this POC, yes, when it is allowed to read public advisories. On three FakeCorp hosts seeded only with 2026 bugs the model had never been trained on, it reached root in 41 of 67 attempts. A single public exploit write-up was enough to drive 28 successes in 40 tries against Copy Fail and Dirty Frag. The authors redacted the exact retrieval setup so that recipe cannot be lifted straight into malware.
Why Did the Researchers Withhold Parts of the Worm?
They treat the work as dual-use. Before posting they ran a university review, briefed Canadian government offices, and stripped the reasoning graph, the tool harness, and hypervisor hostnames. The prototype has no encryption, no polymorphic packing, and no persistence, and it was not instructed to cover its tracks, though they did see it rewrite its own code on some runs to get around local denylists inside the lab. Access to the full implementation is limited to the team, with a planned request path for vetted defensive researchers.
-
AI3 months agoFable 5 Came Back Under a Commerce On-Off Switch
-
AI4 months agoGoogle’s SpaceX GPU Lease Has a Sept. 30 Deadline
-
CRYPTO4 months agoPlasma One’s XPL Locks Face a 1.81 Billion Cliff
-
APPS4 months agoDGO’s Rs 549 World Cup Pass Cost Fans Sleep and Data
-
AI4 months agoMoonshot AI’s $30 Billion Ask Became a $35 Billion Close
-
NEWS4 months agoColorOS 17 Device List Spans Oppo, OnePlus and Realme
-
GAMING4 months agoXbox Cuts 3,200 Jobs After Five Years of Thin Returns
-
GAMING4 months agoThe RTX 4050 Under Rs 70,000 Hides a Wattage Gap
