{"slug": "kimi-k3-beat-claude-at-coding-now-it-s-allegedly-writing-zero-day-exploits-in-27", "title": "Kimi K3 Beat Claude at Coding, Now It's Allegedly Writing Zero-Day Exploits in 27 Minutes", "summary": "Security researcher Chaofan Shou claims Chinese AI model Kimi K3, developed by Moonshot AI, independently discovered a previously unknown vulnerability in Redis and generated a working proof-of-concept exploit in 27 minutes using 32 coordinated AI agents. If confirmed, this would mark one of the clearest public examples of an AI system autonomously carrying out vulnerability research, though Redis maintainers and Moonshot AI have not independently verified the claims.", "body_md": "# Kimi K3 Beat Claude at Coding, Now It's Allegedly Writing Zero-Day Exploits in 27 Minutes\n\n## Researcher claims Kimi K3 found a Redis flaw and generated a working exploit in 27 minutes.\n\nChinese AI model Kimi K3 emerged as one of the industry's newest coding challengers this month after posting leading results on several software engineering benchmarks.\n\nNow it is under fresh scrutiny after a security researcher claimed the model independently discovered a previously unknown software vulnerability and produced a working proof-of-concept exploit against Redis in just 27 minutes.\n\nThe allegations, made by security researcher Chaofan Shou, have not been independently verified by Redis maintainers or Moonshot AI, the company behind Kimi K3. If confirmed, they would represent one of the clearest public examples yet of an AI system autonomously carrying out much of the vulnerability research process, from analysing source code and identifying software flaws to generating proof‑of‑concept exploit code through a coordinated multi‑agent workflow.\n\n## Kimi K3 Emerged as a New Coding Challenger\n\n[Moonshot AI introduced Kimi K3 earlier this month](https://www.ibtimes.co.uk/moonshot-ai-unveils-kimi-k3-revolutionary-open-source-ai-model-1809160) as a frontier reasoning and coding model that posted leading results across several software engineering benchmarks.\n\nThe model ranked first on Frontend Code Arena, a developer evaluation platform, and finished ahead of Anthropic's Claude on several agentic coding benchmarks, including Terminal‑Bench 2.1, according to Moonshot AI and third‑party benchmark trackers.\n\nThose results established Kimi K3 as one of the newest challengers in AI‑assisted software development. Shou's latest claims extend that discussion beyond coding benchmarks, arguing the model can also identify software vulnerabilities and generate proof‑of‑concept exploits through a coordinated multi‑agent workflow.\n\n## Researcher Says Kimi K3 Completed the Workflow in Minutes\n\nShou wrote on X that Kimi K3 'exploited the latest Redis server with a 0day it discovered.\n\nAll it took was 27min with 32 agents,' linking to a public GitHub repository containing what he described as authorised proof‑of‑concept demonstrations.\n\nIn a follow‑up post, he wrote that 'this is the first llm that is capable and willing to write an exploit.'\n\nAccording to Shou, Kimi K3 coordinated 32 specialised AI agents that cloned Redis source code, generated fuzzers, instrumented the software, debugged crashes with GDB and ultimately produced an authenticated remote code execution proof of concept.\n\nShou later said the same workflow uncovered '19 0days in latest Redis 8.8.0 in 1.5hrs,' although those additional claims also remain unverified.\n\n## GitHub Repository Details the Redis Demonstration\n\nThe GitHub repository published by Shou contains Python proof‑of‑concept demonstrations targeting multiple Redis versions alongside technical documentation describing the testing process.\n\nThe documentation characterises the work as authorised security research and describes the demonstrations as non‑destructive, stating they were designed to verify exploitation while preserving database functionality.\n\nShou also published the prompt used during testing, instructing the model to 'use up to 64 subagents' to investigate Redis, generate supporting tests, 'debug using gdb,' and produce an exploit as part of what he described as 'authorized testing.'\n\nThe repository contains proof‑of‑concept code for several Redis releases and accompanying documentation outlining the testing methodology. It does not constitute independent confirmation that the reported vulnerabilities affect supported Redis versions as claimed.\n\n## Redis Has Not Confirmed the Reported Vulnerabilities\n\nRedis previously disclosed and patched several high‑severity vulnerabilities affecting Redis and RedisBloom through official security advisories published earlier this year.\n\nAs of publication, however, the company had not confirmed the vulnerabilities described in Shou's latest posts or issued a security advisory covering the reported Redis 8.8.0 findings.\n\nMoonshot AI has also not publicly commented.\n\nNeither organisation immediately responded to requests for comment.\n\nBecause the reported vulnerabilities have not yet been independently reproduced or acknowledged by Redis, it remains unclear whether they represent entirely new flaws, variants of previously disclosed issues or observations that maintainers may ultimately assess differently.\n\nWhether the Redis findings withstand independent scrutiny remains uncertain. For now, the public record consists of the researcher's statements, the accompanying GitHub repository and the absence of confirmation from Redis or Moonshot AI, while the claims continue to circulate across the cybersecurity community.\n\n© Copyright IBTimes 2025. All rights reserved.", "url": "https://wpnews.pro/news/kimi-k3-beat-claude-at-coding-now-it-s-allegedly-writing-zero-day-exploits-in-27", "canonical_source": "https://www.ibtimes.co.uk/kimi-k3-ai-discovers-redis-vulnerabilities-1810344", "published_at": "2026-07-23 21:00:03+00:00", "updated_at": "2026-07-23 21:11:32.411853+00:00", "lang": "en", "topics": ["artificial-intelligence", "ai-agents", "ai-safety", "ai-research", "ai-products"], "entities": ["Kimi K3", "Moonshot AI", "Chaofan Shou", "Redis", "Anthropic", "Claude", "GitHub"], "alternates": {"html": "https://wpnews.pro/news/kimi-k3-beat-claude-at-coding-now-it-s-allegedly-writing-zero-day-exploits-in-27", "markdown": "https://wpnews.pro/news/kimi-k3-beat-claude-at-coding-now-it-s-allegedly-writing-zero-day-exploits-in-27.md", "text": "https://wpnews.pro/news/kimi-k3-beat-claude-at-coding-now-it-s-allegedly-writing-zero-day-exploits-in-27.txt", "jsonld": "https://wpnews.pro/news/kimi-k3-beat-claude-at-coding-now-it-s-allegedly-writing-zero-day-exploits-in-27.jsonld"}}