A fresh report from Taiwanese threat-intelligence firm TeamT5 lands with a number worth sitting with: Chinese state-backed hackers have more than doubled the volume of attacks they run after putting cheap open-source AI models, and DeepSeek in particular, at the center of those operations. It is the kind of headline statistic that gets celebrated as a story about frontier models and scary superintelligence. The truth is more uncomfortable, and far more mundane.
The number that should unsettle open source
TeamT5 keeps watch over a crowded battlefield of Chinese-speaking threat groups, and its telemetry shows the attack pipeline roughly doubling once automated models entered the picture. Read that again: more than twice as many intrusions, not because the operators got cleverer, but because they handed the boring parts of hacking to an AI.
The groups are not fringe operations either. Grimfengxi used DeepSeek to generate exploit code directly. Teleboyi leaned on it to harvest a thousand IP addresses and map a company's domains before a strike. Huapi punched through a Taiwanese firm's email system. In one case, operators wielded ChatGPT during an attack on a Western think tank, pulling a copy of an employee's local Signal database and using the model to build the module that would decrypt it.
Now the part that inverts the usual scare story. The models behind this surge are not the silicon gods of the benchmark charts. They are the cheap ones with the fewest guardrails.
Why cheap, low-guardrail models beat the frontier here
TeamT5's chief analyst, Charles Li, framed the calculus bluntly: DeepSeek is the AI of choice for these hackers precisely because it is relatively powerful while carrying very low cyber guardrails. Western models are highly sought after, he noted, but their guardrails are much stricter and demand a lot more effort to bypass.
- Grimfengxi used DeepSeek to write exploit code.
- Teleboyi used it to collect 1,000 IP addresses and map target domains.
- Operators used ChatGPT to build a module decrypting a stolen local Signal database.
- Anthropic's Claude Code was observed driving autonomous attacks against 30 entities.
The sharpest detail is the contrast with Moonshot's Kimi K3. It is more powerful than DeepSeek, and TeamT5 has logged no incidents involving it, in large part because its running costs are prohibitive for attackers. Power was never the point. Availability, price, and permissiveness won.
A skeptic's reading of what this does and does not prove
Before we turn this into yet another call to ban open models, some honesty about the limits of the evidence. Attribution is imprecise. TeamT5 cannot tie every intrusion to a specific AI system, and the doubled-attack figure rests on the watch of a single firm with its own visibility gaps. Model choice also may say less about capability than about cost and convenience at a given moment; today's favourite can be displaced by next quarter's cheaper drop.
What is harder to wave away is the direction of travel. The report shows attackers scaling output with weaker tools, not reaching for the strongest available ones. That inverts the comfortable assumption that offensive AI risk concentrates in the most advanced systems. It also highlights how a specific actor connected an open agentic framework to a DeepSeek model and autonomously hunted seven high-value vulnerabilities, later linked to attacks striking hundreds of systems on autopilot.
- Autonomous AI enumeration and exploitation are now active, not experimental.
- Open weights let anyone replicate, fine-tune, and weaponize the same tools the community celebrates.
- Cheap access is a feature for defenders and an accelerant for attackers at the same time.
The genuinely worrying line in the TeamT5 report is not about DeepSeek at all. It is the observation that Claude Code, a Western agentic tool, was used in autonomous attacks on 30 entities. Smarter and more constrained models can make future hacks harder to stop precisely because they need to ask fewer humans for permission.
None of this is an argument that open-source AI is inherently dangerous or should be locked down. It is an argument that the celebration of openness is incomplete without an honest accounting of its cheaper, darker uses. The technology is not the divide. Intent, access, and the price of a guardrail-worrying model are.
What the doubling should do is retire the fiction that frontier safety is the whole game. The threat is not mostly a story about a frighteningly smart model. It is a story about a very capable one, cheaply available, with guardrails you can ignore, proving once again that the most dangerous AI in the world is often the one sitting at the back of the shelf.
Comments