Developer of hacked bank tool ARTEX pulls it from public GitHub The developer of ARTEX, an open-source AI penetration-testing agent that CrowdStrike linked to breaches at nine South Korean banks, pulled the project from GitHub on Thursday and said it will be converted to closed source with no further public versions or maintenance support. CrowdStrike said a China-based individual around 26 years old combined ARTEX with Anthropic's Claude Code, DeepSeek, Zhipu AI's GLM and xAI's Grok to automate reconnaissance and intrusion; Shinhan Bank and Yegaram Savings Bank account for the two largest known exposures at roughly 25,000 and 40,000 customer records respectively. ARTEX had been publicly downloadable under an AGPL-3.0 license since July 26, so removing the repository does not eliminate existing forks, mirrors and local copies. The tool blamed for breaching nine South Korean banks just went dark. The code that did the damage is already out in the world, and locking the repository now won't claw it back. On Thursday, the developer behind ARTEX, the open-source AI penetration-testing agent CrowdStrike linked to a wave of South Korean bank breaches, pulled the project's GitHub page and said it would never be updated again. "Given the misuse of the tool, the ARTEX project will no longer be updated and will be converted to closed source," the developer, who goes by the handle Autumn-27, wrote on GitHub, according to Reuters. "No further versions will be released to the public nor will maintenance support be provided." That's the new development. The breach itself is old news by now. CrowdStrike said this week that a China-based individual, believed to be around 26 years old, strung together ARTEX with Anthropic's Claude Code and several Chinese large language models, including DeepSeek and Zhipu AI's GLM, plus xAI's Grok: all of it stitched together to automate reconnaissance and intrusion across South Korean financial institutions. At least nine banks and lenders have disclosed or been named in local reporting as targets since late September, among them Shinhan Bank, KB Kookmin Bank, Hana Bank and BNK Busan Bank, according to the Korea JoongAng Daily. Yegaram Savings Bank and Shinhan Bank account for the two largest known exposures, roughly 40,000 and 25,000 customer records respectively. ARTEX itself isn't exotic. Autumn-27 published it on GitHub on July 26 under an AGPL-3.0 license, pitched as a legitimate automation layer for penetration testers. It strings together LLM calls to scan networks, find weaknesses and chain exploits: the kind of workflow a security team would otherwise do by hand. Infosecurity Magazine reported that CrowdStrike's researchers walked through exposed operator logs tied to the campaign. The attacker's tooling, prompts and intermediate outputs were sitting in the open, which is partly how the attribution came together in the first place. Here's the problem with the developer's move: it closes the door after the car has already left the garage. ARTEX has been live and downloadable since July. Anyone who wanted a copy, whether a penetration tester, a researcher, or the person who hit Shinhan Bank, has had more than two months to clone it. Taking the GitHub page down stops new users from discovering the project and signals that Autumn-27 doesn't want to be associated with what happened. It does nothing about the forks, mirrors and local copies that almost certainly exist already. AI hacking tool traced in South Korean bank breaches as CrowdStrike flags wider trend https://startupfortune.com/ai-hacking-tool-traced-in-south-korean-bank-breaches-as-crowdstrike-flags-wider-trend/ Shinhan Bank, KB Kookmin, Hana and four other South Korean lenders have disclosed breaches since September 29, with roughly 65,000 customer records exposed and an open-source Chinese-language AI tool found on the attackers' servers. - AI hacking tool traced in South Korean banks https://startupfortune.com/ai-hacking-tool-traced-in-south-korean-bank-breaches-as-crowdstrike-flags-wider-trend/ - Chinese language hacking tool South Korean bank breaches https://startupfortune.com/ai-hacking-tool-traced-in-south-korean-bank-breaches-as-crowdstrike-flags-wider-trend/ Open-source code doesn't have a recall function. That's the uncomfortable truth sitting underneath every one of these stories, and it isn't new. Security researchers have warned for years about a split. Offensive tools released as open source, port scanners, exploit frameworks, and now AI-driven penetration agents, divide cleanly into two user bases: the defenders who adopt them to find holes before attackers do, and the attackers who adopt them because someone already did the engineering work. Metasploit faced the same argument two decades ago and survived it by becoming indispensable to defenders faster than it became indispensable to criminals. ARTEX never got the chance to make that case. It went from launch to implicated in a nine-bank breach in under three months, and now it's closed before the defensive side ever caught up. The more useful question isn't whether Autumn-27 made the right call. It's what happens to the next ARTEX. CrowdStrike's own 2026 Threat Hunting Report, cited by CRN Asia, found AI-driven intrusion activity up 89% year over year. The tooling behind that growth is overwhelmingly open and overwhelmingly easy to combine: a penetration-testing agent here, a cheap or free LLM API there. DeepSeek and GLM are both freely accessible outside China, and nothing about this incident changes that. If anything, the lesson for whoever builds the next ARTEX is a simple one: dual-use AI agents draw scrutiny fast once they're linked to a real breach. The fix on offer, going closed-source after the fact, protects the developer's name more than it protects the next bank. South Korea's Financial Services Commission has ordered a broader review of how the country's banks defend against AI-assisted intrusions, according to Let's Data Science. That review will matter more than ARTEX's GitHub status. The code is out there. The commission's job now is making sure the next version of this attack, built on whatever tool replaces ARTEX, doesn't work. Also read: Nvidia-Backed Firmus Withdraws Its ASX IPO After Investors Balked https://startupfortune.com/nvidia-backed-firmus-withdraws-its-asx-ipo-after-investors-balked/ • Lumentum says its AI optical parts are sold out all the way to 2029 https://startupfortune.com/lumentum-says-its-ai-optical-parts-are-sold-out-all-the-way-to-2029/ • Chip stocks sink into a correction even as Samsung posts record profit https://startupfortune.com/chip-stocks-sink-into-a-correction-even-as-samsung-posts-record-profit/ This article is posted in AI News https://startupfortune.com/category/ai/ , check it out for more related stories. Shinhan Bank Data Breach Points to AI Agents Hacking Korean Banks https://startupfortune.com/shinhan-bank-data-breach-points-to-ai-agents-hacking-korean-banks/ KB Kookmin Bank and Hana Bank also disclosed leaks of 119 and 89 customers within days, and detection took Shinhan over 15 hours, KB Kookmin nearly three days, exposing how slow banks are to notice AI-driven intrusions. - how AI agents are hacking Korean banks https://startupfortune.com/shinhan-bank-data-breach-points-to-ai-agents-hacking-korean-banks/ - Shinhan Bank data breach security vulnerabilities exposed https://startupfortune.com/shinhan-bank-data-breach-points-to-ai-agents-hacking-korean-banks/ Join the discussion Open in the community → https://startupfortune.com/community/ Almost there. Sign in and your reply posts straight away.