An AI company just admitted its chatbot had some unwelcome users: state hackers doing reconnaissance.
The company banned accounts it says were potentially tied to publicly reported North Korean state-linked threat actors. Those accounts had reportedly used the AI to research intrusion tooling, draft phishing material, work on malware, and dig into cryptocurrency targets. The company did not disclose how many accounts were involved or name specific campaigns tied to the bans.
This fits a pattern security researchers have flagged for years: North Korean state hackers, chronically underfunded and heavily sanctioned, treat cryptocurrency theft as a primary revenue line, not a side hustle. An AI model that speeds up phishing copy or intrusion research is a productivity tool for a nation-state, same as it is for anyone else.
Banning a handful of accounts does not stop a state intelligence agency. It just means they open a new account, or move to a model with fewer guardrails. Account bans are a paper trail for researchers, not a wall for attackers.