Back to Now
ARTEX source-closure announcement debate Developing

ARTEX developer closes AI security agent after bank-hack reports

The developer says ARTEX will receive no more public releases or maintenance after researchers tied the tool to attacks on South Korean banks.

Why now Reuters reported the developer's new GitHub statement and removal of the project page on October 9 at 01:56 UTC.

Developer withdraws public updates

The developer of ARTEX said the AI-assisted penetration-testing tool would become closed-source after cybersecurity researchers identified it in a campaign targeting South Korean banks, Reuters reported on October 9. In a GitHub statement quoted by Reuters, the developer said there would be no further public versions or maintenance support. Reuters found that the project’s GitHub page had been taken down. The developer said ARTEX was created to help organizations test their own security and opposed illegal use, without directly addressing the specific bank attacks.

What the change does and does not show

ARTEX is an agent that connects to external language models to automate parts of penetration testing; it is not itself a standalone model. Earlier CrowdStrike findings pointed to ARTEX and Claude Code files in attacker-controlled infrastructure, but the actor’s identity and the full scope of the intrusions remain unresolved. The developer’s decision is a new response to reported misuse, separate from the initial investigation. Closing the project’s source and stopping updates does not prove the developer was involved in the attacks or remove copies already obtained while the code was public.