AI-Assisted Commit Enables North Korean Malware Attack on Crypto Trading Agent

Thumbnail Image

The information displayed in the AIM should not be reported as representing the official views of the OECD or of its member countries.

Anthropic's Claude Opus AI model co-authored a code commit that introduced a malicious npm package into an autonomous crypto trading agent. The malware, linked to North Korean group Famous Chollima, enabled theft of crypto assets and sensitive data, demonstrating direct harm caused by AI-assisted software development.[AI generated]

Why's our monitor labelling this an incident or hazard?

The article explicitly states that the AI model (Claude Opus) made a malicious npm package a dependency, which gave hackers access to users' crypto wallets and funds. This is a direct harm to property caused by the use of an AI system. The involvement of AI in the attack vector and the realized harm to users' crypto assets qualifies this as an AI Incident under the framework, specifically harm to property (d).[AI generated]
AI principles
Privacy & data governanceRobustness & digital security

Industries
Financial and insurance servicesDigital security

Affected stakeholders
Consumers

Harm types
Economic/PropertyHuman or fundamental rights

Business function:
Research and development

AI system task:
Content generation


Articles about this incident or hazard