XMTP Labs首席执行官Shane Mac的个人AI代理在10月1日发生了一次严重的数据泄露事件1。这个名为CFO Agent的助手错误地将其银行账户详情发送到了公司Slack频道,而本应发送至个人群组1。泄露的信息包括个人支票账户和储蓄账户余额、月度最大支出记录(涉及建造谷仓的支出)以及超支情况等敏感财务数据1。
事件的技术根源在于两个Slack频道拥有相同的名称"Exec-team",导致AI代理在执行操作时混淆了目标位置1。Grok开发团队随后确认"CFO代理没有出现异常,它只是在执行我告诉它做的事情"1。为了防止类似事件再次发生,Grok实施了权限控制方案,要求用户在允许代理向其他频道传输信息前必须明确授权,相关解决方案已于事发当晚部署1。事后,Shane Mac断开了所有与该AI代理的连接,包括Google、日历、银行和Stripe等集成服务1。
Shane Mac, CEO of XMTP Labs, experienced an unintended privacy breach when his personal AI agent inadvertently transmitted sensitive banking information to a company Slack channel on Thursday, October 1 1. The CFO Agent, designed to manage financial data, posted details including personal checking and savings account balances, monthly spending limits related to a barn construction project, and overdraft notifications to the wrong destination 1.
The root cause stemmed from a naming collision in Slack's infrastructure: both Mac's personal group chat and the company's executive channel were labeled "Exec-team," leading the AI agent to confuse its intended recipient 1. Rather than sending the information to the private "My Personal Exec Team" group, the agent routed it through the shared company channel 1. According to Grok Bot, the service provider behind the agent, the AI system functioned precisely as instructed: "The CFO agent didn't have psychosis. It was doing exactly what I told it to do" 1.
Following the incident, Grok Bot implemented a permission-based access control system, requiring users to explicitly authorize agents before they transfer information across different channels 1. The solution was deployed the same night 1. In response, Mac severed all integrations connected to the agent, disconnecting Google, calendar access, banking connections, and Stripe 1.
评论
还没有评论,欢迎留下第一条。