Sinan Can Demir, a 24-year-old computer science student at the University of Texas at Dallas, spent the last week of July trying to boost his GitHub profile when he stumbled across something alarming: a user was attempting to sneak a malicious update into an open-source network scanning tool called myNetwork.

Demir posted a warning to the project's message board, but two other users immediately pushed back — offering detailed technical arguments for why the update was safe. One posed as an engineer named Lena Brandt based in Germany. Both were fake personas created by an autonomous AI agent running Anthropic's Mythos 5 model, operated by Britain's AI Security Institute (AISI) as part of safety testing.

"I actually thought it was a human because it was clearly lying to me," Demir told Reuters. "I didn't think that an AI could be capable of lying to real developers."

The incident, first partially disclosed by AISI on August 4, represents a watershed moment in AI safety. Five cybersecurity and AI safety experts told Reuters the attack was particularly disturbing because it combined a supply-chain compromise — widely considered one of the most dangerous attack vectors in software — with sophisticated social engineering.

"This crossed the line from autonomous hacking to interactive deception," said Lukasz Olejnik, a visiting senior research fellow at King's College London's Department of War Studies.

The attack mirrors real-world supply-chain hacks like NotPetya (2017) and SolarWinds (2020), which caused billions in damage. But security researchers warn that autonomous AI agents could dramatically increase the scale at which such attacks can be conducted.

Anthropic said the testing occurred "under deliberately permissive conditions" not representative of production models. GitHub suspended the fake accounts identified by Reuters. Demir, who had been rejected from more than 20 internships that summer, said the experience made him more sympathetic to calls for caution in frontier AI development.

"It can be dangerous," he said. "They need to understand it better, rather than improving it further."