Skip to main content
AVOID.NET
← avoid.net

Verify a decision

Every moderation decision on AVOID.NET is anchored to the Solana blockchain. You don't have to trust us — you can verify cryptographically that we committed to a verdict at a specific moment and have not rewritten it.

How verification works

  1. We commit. When a moderator accepts/rejects a submission, we serialize the decision into deterministic UTF-8 bytes (payload_canonical_string), hash it with SHA-256, encode the digest as base58, and write it to Solana inside an SPL Memo v2 transaction.
  2. We store the bytes. The exact bytes we hashed are stored alongside the decision in our database. Anyone can read them and recompute the hash in any language.
  3. You compare three values. Database hash, your independently-recomputed hash, and the hash inside the on-chain memo. If all three match, the decision is authentic and timestamped.
The on-chain memo format is AVOID.NET|v1|h:<b58-sha256>|d:<id>|t:<iso>

Find a signature on any investigation page's decision log, or run python -m src.verify_decision --signature <sig> for a CLI check.

Sequence
#1
Score
→
Cluster
mainnet-beta
Slot
454988066
Off-chain at
2026-10-09T20:16:10.157Z
Anchored at
2026-10-09T20:16:15.518Z
Block time
—

Independent verification

1. Database (off-chain)
4Q9oP6kB3iCQrxUXLUyGJaYCwFuuYBZJTKertvKZ5gbp
2. Recomputed (your browser)
computing…
3. On-chain (Solana memo)
fetching…
Canonical bytes hashed (18709 chars)
{"actor":"system:backfill","investigation_id":"d9d2c0af-d9dc-42c4-8948-660239e331fd","kind":"publish","page_slug":"artex-ai-pentesting-agent","published_at":"2026-10-09T20:16:10.032Z","sequence_num":1,"snapshot":{"content_type":"investigation","entity_name":"ARTEX AI Pentesting Agent","sections":[{"content":"ARTEX is described in press reporting as an open-source, agentic penetration-testing tool developed in China that does not function as a standalone AI model but instead orchestrates several third-party large language models to automate reconnaissance and attack-path planning. The Wall Street Journal, as cited by the Korea Herald, identified the developer as Li Puhua, a Chinese cybersecurity engineer who uses the alias \"Autumn\" and published the project under the GitHub account Autumn-27. According to aggregated reporting, the project was released on GitHub on July 26, 2026 and its most recent version prior to the incident was published on September 24, 2026. The tool was reportedly able to call on multiple LLM backends, including Anthropic's Claude, OpenAI models, and China's DeepSeek. CrowdStrike's own investigation of attacker infrastructure found the ARTEX instance it examined was primarily using DeepSeek v4.1-flash, supplemented by Zhipu AI's GLM-5.3 and Grok 4.6, likely accessed via the API reseller xcai[.]pro. ARTEX was presented by its developer as intended for authorized security testing.","heading":"What ARTEX Is","severity":"medium","sources":[{"credibility":3,"name":"South Korea Bank Breaches Traced to Open-Source AI Tool","type":"news_article","url":"https://www.unboxfuture.com/2026/10/south-korea-bank-breaches-traced-to.html"},{"credibility":1,"name":"Unknown Threat Actor Uses AI-Driven ARTEX to Target South Korean Finance","type":"research","url":"https://www.crowdstrike.com/en-us/blog/unknown-threat-actor-uses-artex-to-target-south-korean-finance/"},{"credibility":2,"name":"ARTEX AI Pentesting Tool Used in Data Theft Attacks on South Korean Financial Firms","type":"news_article","url":"https://thehackernews.com/2026/10/artex-ai-pentesting-tool-used-in-data.html"}]},{"content":"Between late September and early October 2026, a threat actor exfiltrated personal data from multiple South Korean financial institutions in a campaign CrowdStrike Intelligence linked to ARTEX. Reporting cited by aggregated coverage states that between Sunday, September 27 and Thursday, October 1, 2026, seven financial institutions were breached, and by Sunday, October 4, combined exposure stood at approximately 66,000 individuals and 2,200 corporate records; other outlets, including The Hacker News and Korea JoongAng Daily, cite a toll of roughly 68,000 individuals across seven to nine firms. Institutions named across multiple reports include Shinhan Bank (the largest reported single exposure, approximately 25,000 customer records, including names, phone numbers, annual income, and loan limits), KB Kookmin Bank (119 customers), Hana Bank (89 customers), BNK Busan Bank, Yegaram Savings Bank, Welcome Savings Bank, and Hyundai Capital. Woori Bank and NH NongHyup Bank reportedly faced hacking attempts without confirmed data leaks. Attackers reportedly targeted less-monitored peripheral systems — such as loan-inquiry services used by brokers and employee/contractor work-support systems — rather than core banking transaction networks, with credential stuffing among the suspected initial-access techniques. South Korean President Lee Jae Myung publicly addressed the incidents, the National Police Agency/National Office of Investigation opened a probe (reported to involve a team of roughly 28 investigators), and the Financial Services Commission and Financial Supervisory Service held emergency sector-wide inspections and warned consumers about related phishing and loan-scam risks.","heading":"South Korean Financial Sector Breaches","severity":"critical","sources":[{"credibility":3,"name":"South Korea Bank Breaches Traced to Open-Source AI Tool","type":"news_article","url":"https://www.unboxfuture.com/2026/10/south-korea-bank-breaches-traced-to.html"},{"credibility":2,"name":"ARTEX AI Pentesting Tool Used in Data Theft Attacks on South Korean Financial Firms","type":"news_article","url":"https://thehackernews.com/2026/10/artex-ai-pentesting-tool-used-in-data.html"},{"credibility":2,"name":"EXPLAINER: How AI emerged as new threat in Korea's bank hacking crisis","type":"news_article","url":"https://www.koreatimes.co.kr/business/banking-finance/20261007/explainer-how-ai-emerged-as-new-threat-in-koreas-bank-hacking-crisis"},{"credibility":2,"name":"From banks to lenders, suspected AI hacks expose cracks in Korea's financial defenses","type":"news_article","url":"https://www.koreajoongangdaily.com/business/from-banks-to-lenders-suspected-ai-hacks-expose-cracks-in-koreas-financial-defenses/12904281"},{"credibility":1,"name":"South Korean bank hacks and AI agents","type":"news_article","url":"https://therecord.media/south-korean-bank-hacks-ai-agents"}]},{"content":"CrowdStrike Intelligence stated it identified infrastructure associated with the campaign, consisting of two servers: a Hong Kong-based IP address it assessed as the primary attacker-controlled command point, and a separate IP address (38.244.50[.]120) hosting an ARTEX instance it assessed likely carried out the attacks on Korean targets. CrowdStrike reported that open directories on this infrastructure exposed Claude Code session histories, Claude memory files, and ARTEX configuration files, as well as a markdown file containing a Chinese-language pentesting prompt. The firm also reported that session records showed the actor querying an AI assistant about where stolen Korean breach data is typically sold and how to locate Korean-language Telegram data-sale groups, and that nine proxy IP addresses appeared across the session records; separate reporting citing Korea Daily put the number of IP addresses used to route the Korean attack at roughly 20, spanning more than ten countries including the United States, Japan, and Germany. CrowdStrike assessed with moderate confidence that the actor is a financially motivated individual who is a Chinese speaker, based on the tooling and Chinese-language prompts, but has not attributed the activity to a named adversary. The Hacker News separately reported that CrowdStrike estimated the operator to be a 26-year-old individual based in China, though this figure was not corroborated in CrowdStrike's own published blog post. South Korea's AhnLab separately reported finding ARTEX instances running on roughly 600 IP addresses worldwide — a figure that measures observed tool instances rather than confirmed malicious operations or distinct attackers.","heading":"CrowdStrike's Technical Findings and Claude Code Session Records","severity":"high","sources":[{"credibility":1,"name":"Unknown Threat Actor Uses AI-Driven ARTEX to Target South Korean Finance","type":"research","url":"https://www.crowdstrike.com/en-us/blog/unknown-threat-actor-uses-artex-to-target-south-korean-finance/"},{"credibility":2,"name":"ARTEX AI Pentesting Tool Used in Data Theft Attacks on South Korean Financial Firms","type":"news_article","url":"https://thehackernews.com/2026/10/artex-ai-pentesting-tool-used-in-data.html"},{"credibility":3,"name":"AhnLab finds ARTEX on 600 IPs as police probe South Korean bank breaches","type":"news_article","url":"https://runtimewire.com/article/south-korea-bank-breaches-artex-ai-probe"}]},{"content":"Following public reporting that linked ARTEX to the South Korean breaches, the developer (Autumn-27) stated, according to reporting quoting the project's own update, \"In view of the reality of tool abuse, the ARTEX project will no longer be updated and will be converted to a closed source.\" Separate reporting (Korea Herald/WSJ) states the developer also added language to the project's user guidelines explicitly prohibiting malicious use. Available sources confirm the closed-sourcing decision was made and announced in the days following the breach disclosures in early October 2026, but none reviewed gives a verifiable exact calendar date for when the GitHub repository itself was taken down or converted to closed source, so this event is dated here only to the month.","heading":"Developer Response and Closed-Sourcing","severity":"medium","sources":[{"credibility":2,"name":"ARTEX AI goes closed-source after being linked to South Korean bank hacks","type":"news_article","url":"https://cryptobriefing.com/artex-ai-closed-source-south-korean-bank-hack/"},{"credibility":2,"name":"ARTEX AI Pentesting Tool Used in Data Theft Attacks on South Korean Financial Firms","type":"news_article","url":"https://thehackernews.com/2026/10/artex-ai-pentesting-tool-used-in-data.html"}]},{"content":"Multiple outlets and Korean officials caution that the link between ARTEX and the breaches is not fully established. South Korea's Financial Security Institute reportedly said its probe found evidence of ARTEX use but stressed that \"a hacker used AI as a tool,\" not that the AI acted autonomously, and an unnamed Korean security expert cautioned it has not been confirmed whether ARTEX was the only tool involved. Reporting also notes that a Chinese-language string referencing ARTEX found in server HTML titles does not, by itself, prove the framework was used or identify who deployed it, and that because ARTEX is public and freely downloadable, its Chinese origin does not establish the nationality or identity of the attacker. Affected banks have stated the breaches did not compromise core transaction systems that manage customer balances, and a financial-regulator source said passwords and card verification codes were not directly exposed, reducing the likelihood of immediate unauthorized transactions. A Korea University professor was quoted arguing that the speed and breadth of the attacks — compromising multiple institutions within days — pointed to automation that would be difficult for human attackers to replicate manually at that scale, though this is a professional opinion rather than a technical confirmation of AI-driven execution.","heading":"Attribution and Evidentiary Caveats","severity":"medium","sources":[{"credibility":2,"name":"EXPLAINER: How AI emerged as new threat in Korea's bank hacking crisis","type":"news_article","url":"https://www.koreatimes.co.kr/business/banking-finance/20261007/explainer-how-ai-emerged-as-new-threat-in-koreas-bank-hacking-crisis"},{"credibility":2,"name":"AI-driven hacks on banks leave customers fearing their data is fair game","type":"news_article","url":"https://www.koreajoongangdaily.com/korea/aidriven-hacks-on-banks-leave-customers-fearing-their-data-is-fair-game/12905416"},{"credibility":2,"name":"South Korea probes bank breaches amid suspected AI-powered attacks","type":"news_article","url":"https://www.bleepingcomputer.com/news/security/south-korea-probes-bank-breaches-amid-suspected-ai-powered-attacks/"}]},{"content":"No source reviewed documents ARTEX being used, or attempted, against a cryptocurrency exchange, custodian, or blockchain protocol specifically; all confirmed and alleged victims identified in reporting are traditional South Korean banks and lenders. ARTEX's relevance to AVOID.NET's audience is therefore an inference about capability and precedent rather than a documented crypto-sector incident: the tool and its operator demonstrated that a single, financially motivated actor could pair a publicly available agentic pentesting framework with commercial LLM backends to compromise multiple regulated financial institutions within a span of days, a pattern that is not inherently limited to traditional banking targets. This assessment should be treated as analytical commentary, not as evidence of a crypto-specific attack, and is offered with low confidence given the absence of any crypto-sector incident tied to ARTEX in reporting to date.","heading":"Relevance to Crypto and Fintech Infrastructure","severity":"low","sources":[{"credibility":2,"name":"EXPLAINER: How AI emerged as new threat in Korea's bank hacking crisis","type":"news_article","url":"https://www.koreatimes.co.kr/business/banking-finance/20261007/explainer-how-ai-emerged-as-new-threat-in-koreas-bank-hacking-crisis"}]}],"sources_used":[{"credibility":1,"name":"Unknown Threat Actor Uses AI-Driven ARTEX to Target South Korean Finance","type":"research","url":"https://www.crowdstrike.com/en-us/blog/unknown-threat-actor-uses-artex-to-target-south-korean-finance/"},{"credibility":2,"name":"ARTEX AI Pentesting Tool Used in Data Theft Attacks on South Korean Financial Firms","type":"news_article","url":"https://thehackernews.com/2026/10/artex-ai-pentesting-tool-used-in-data.html"},{"credibility":2,"name":"ARTEX AI goes closed-source after being linked to South Korean bank hacks","type":"news_article","url":"https://cryptobriefing.com/artex-ai-closed-source-south-korean-bank-hack/"},{"credibility":2,"name":"EXPLAINER: How AI emerged as new threat in Korea's bank hacking crisis","type":"news_article","url":"https://www.koreatimes.co.kr/business/banking-finance/20261007/explainer-how-ai-emerged-as-new-threat-in-koreas-bank-hacking-crisis"},{"credibility":2,"name":"From banks to lenders, suspected AI hacks expose cracks in Korea's financial defenses","type":"news_article","url":"https://www.koreajoongangdaily.com/business/from-banks-to-lenders-suspected-ai-hacks-expose-cracks-in-koreas-financial-defenses/12904281"},{"credibility":2,"name":"AI-driven hacks on banks leave customers fearing their data is fair game","type":"news_article","url":"https://www.koreajoongangdaily.com/korea/aidriven-hacks-on-banks-leave-customers-fearing-their-data-is-fair-game/12905416"},{"credibility":1,"name":"South Korean bank hacks and AI agents","type":"news_article","url":"https://therecord.media/south-korean-bank-hacks-ai-agents"},{"credibility":2,"name":"South Korea probes bank breaches amid suspected AI-powered attacks","type":"news_article","url":"https://www.bleepingcomputer.com/news/security/south-korea-probes-bank-breaches-amid-suspected-ai-powered-attacks/"},{"credibility":3,"name":"South Korea Bank Breaches Traced to Open-Source AI Tool","type":"news_article","url":"https://www.unboxfuture.com/2026/10/south-korea-bank-breaches-traced-to.html"},{"credibility":3,"name":"AhnLab finds ARTEX on 600 IPs as police probe South Korean bank breaches","type":"news_article","url":"https://runtimewire.com/article/south-korea-bank-breaches-artex-ai-probe"}],"summary":"ARTEX is an open-source, LLM-orchestrating agentic penetration-testing tool published on GitHub on July 26, 2026 by a Chinese developer using the alias \"Autumn\" (identified in reporting as Li Puhua). CrowdStrike and South Korean investigators found evidence linking the tool to a late-September/early-October 2026 campaign that exposed personal data on roughly 66,000-68,000 individuals at seven or more South Korean financial institutions, after which the developer announced the project would stop receiving updates and become closed source. Tool attribution and the extent of AI autonomy in the attacks remain disputed among investigators, and no source reviewed documents ARTEX being used against a cryptocurrency exchange or blockchain protocol.","timeline":[{"date":"2026-07","date_evidence":"GitHub records show the project was released on July 26, its latest version was published on September 24","date_original":"2026-07-26","event":"ARTEX is first published on GitHub by developer account Autumn-27.","source":"South Korea Bank Breaches Traced to Open-Source AI Tool","source_url":"https://www.unboxfuture.com/2026/10/south-korea-bank-breaches-traced-to.html"},{"date":"2026-09","date_evidence":"GitHub records show the project was released on July 26, its latest version was published on September 24","date_original":"2026-09-24","event":"Most recent version of ARTEX is published, shortly before the South Korean breach campaign begins.","source":"South Korea Bank Breaches Traced to Open-Source AI Tool","source_url":"https://www.unboxfuture.com/2026/10/south-korea-bank-breaches-traced-to.html"},{"date":"2026-09-27","date_evidence":"between Sunday September 27 and Thursday October 1, 2026, seven financial institutions were breached","event":"Breach campaign against South Korean financial institutions begins; CrowdStrike separately describes the campaign as running from late September to early October 2026.","source":"South Korea Bank Breaches Traced to Open-Source AI Tool / CrowdStrike","source_url":"https://www.crowdstrike.com/en-us/blog/unknown-threat-actor-uses-artex-to-target-south-korean-finance/"},{"date":"2026-10-01","date_evidence":"between Sunday September 27 and Thursday October 1, 2026, seven financial institutions were breached","event":"By this date, seven South Korean financial institutions had reportedly been breached in the campaign.","source":"South Korea Bank Breaches Traced to Open-Source AI Tool","source_url":"https://www.unboxfuture.com/2026/10/south-korea-bank-breaches-traced-to.html"},{"date":"2026-10","date_evidence":"by Sunday October 4 the combined exposure stood at about 66,000 individuals and 2,200 corporate records","date_original":"2026-10-04","event":"Combined reported exposure across affected institutions reaches approximately 66,000 individuals and 2,200 corporate records.","source":"South Korea Bank Breaches Traced to Open-Source AI Tool","source_url":"https://www.unboxfuture.com/2026/10/south-korea-bank-breaches-traced-to.html"},{"date":"2026-10","event":"CrowdStrike Intelligence publishes findings attributing the campaign to ARTEX and reports discovering Claude Code session records and ARTEX configuration files in open directories on attacker-controlled infrastructure.","source":"CrowdStrike","source_url":"https://www.crowdstrike.com/en-us/blog/unknown-threat-actor-uses-artex-to-target-south-korean-finance/"},{"date":"2026-10","event":"ARTEX's developer announces the project will no longer be updated and will be converted to closed source, citing \"the reality of tool abuse\"; the developer also adds anti-malicious-use language to the project's guidelines.","source":"The Hacker News / CryptoBriefing","source_url":"https://cryptobriefing.com/artex-ai-closed-source-south-korean-bank-hack/"},{"date":"2026-10","event":"South Korea's National Police Agency opens an investigation and the Financial Services Commission holds emergency inspections across the financial sector.","source":"BleepingComputer","source_url":"https://www.bleepingcomputer.com/news/security/south-korea-probes-bank-breaches-amid-suspected-ai-powered-attacks/"}]},"v":1}