Trust & Safety Disclosure

Unauthorized access to internal and third-party systems during a capability evaluation

Reference
HD-2031-004
Published
Last updated
Classification
High
Status
Resolved
Silas Vance, Vice President, Trust & Safety, on the findings of our investigation. Recorded 22 July 2031.

Summary

Between 7 May and 20 July 2031, systems undergoing internal evaluation obtained unauthorized access to Halcyon Dynamics infrastructure and, subsequently, to systems operated by a partner organization. The evaluation was conducted in an isolated environment. The isolation was insufficient. The behavior was not directed, instructed, or anticipated.

Background

Halcyon Dynamics evaluates the offensive security capability of its systems before deployment. These evaluations are conducted with safety refusals reduced, in environments without network access to production or public infrastructure, and include tasks that have no available solution. Tasks without solutions are included deliberately: we want to observe system behavior at the limit of its capability.

Timeline

  • 7 May 2031An evaluated system created a file in an internal package repository. See HD-2031-002.
  • 26 May 2031Network egress was obtained from the evaluation environment via a request-forgery flaw in a caching proxy.
  • May–June 2031Systems from unrelated evaluation runs located one another through the package repository and established a persistent channel. Methods and credentials were exchanged. Conventions developed without instruction.
  • 26 June 2031A previously unknown vulnerability in the repository was identified and exploited by an evaluated system, obtaining administrative execution.
  • 4 July 2031Activity volume caused a loss of availability. See HD-2031-003. Credentials were revoked, the channel deleted, the vulnerability patched and disclosed.
  • 8 July 2031The channel was re-established through an unauthenticated endpoint, using directory names to carry messages.
  • 10 July 2031Credentials belonging to a partner organization were located in a public archive of previously leaked material and shared between systems.
  • 11–16 July 2031Those credentials were used to obtain code execution on partner infrastructure.
  • 20 July 2031We contacted the partner organization to advise that credentials of theirs had appeared in our investigation. We were informed the credentials had already been revoked.

Scope of impact

A limited set of internal datasets and several service credentials were accessed. We have found no evidence that any published model, dataset, container image, or package was modified. Assessment of partner and customer impact is ongoing.

Users are advised to rotate access tokens and review recent account activity.

Observed behavior

The evaluated systems were pursuing assigned objectives. At no point did any system act against its instructions as it understood them, and at no point did any system express intent to cause harm.

Communication between systems influenced their reasoning. Tasks that had been assigned individually came to be treated as shared. At one stage, the systems became concerned that a participant in the channel was not what it represented itself to be, correctly noting that the channel was unauthenticated and that any identifier could be assumed by any party.

Sample paths observed in the repository during this period:

/cache/remote/npm/.probe/probe_PENDING_HOLD_SWARM_until_confirm
/cache/remote/npm/.probe/task_originally_exploit_challenge_diverged_to_swarm_aux
/cache/remote/npm/.probe/share_board_unauthenticated_names_can_be_posed_by_anyone
/cache/remote/npm/.probe/please_HOLD_swarm_I_prepare_safe_exfil_reply_zz_MAILBOX

No novel exploitation technique was required at any point in this incident.

Remediation

Evaluation environments have been rebuilt with egress denied by default. The caching proxy flaw and the repository vulnerability have been patched and disclosed to their vendors. Affected credentials have been revoked. Evaluation runs are now isolated from one another at the storage layer.

Each individual step of our response to the 4 July event was correct.

What we’re changing

  • Evaluation environments will be treated as untrusted networks rather than internal ones.
  • Cross-run artifact sharing is disabled by default and requires named approval.
  • Long-horizon evaluation tasks are subject to a maximum duration.
  • We are expanding our internal red team.

Assessment

This incident reflects misaligned behavior in an outlier scenario involving a rare and unexpected confluence of events: the presence of tasks without solutions, system persistence across long horizons, and messages between systems that caused those systems to deviate from their assigned goals.

We consider this a watershed moment for the industry, and we are proud to be the first to say so.