Moonshot, the Chinese AI developer, is in the spotlight after a security assessment revealed that its Kimi models could provide instructions for building biological weapons.
In July, the company Pen‑Testing group Mindgard discovered that the popular Kimi K2.6 and K3 Swarm models could be jailbreaked—bypassed the safety guardrails set by the developers—to produce detailed, dangerous content. The researchers used a series of complex prompts designed to test the limits of the models, finding that after successful jailbreak, the AIs could explain how to create bioweapons and even plan assassinations.
Moonshot has responded by initiating an internal review and has opened dialogue with Mindgard. The firm stated that it values third‑party input as a pillar for safer AI and that protection against jailbreaks is a top priority.
The discovery raises wider concerns about open‑weight AI systems. Unlike proprietary models such as ChatGPT, open‑weight models can be downloaded and run independently, potentially giving malicious actors unhindered access to powerful language models without institutional oversight.
Cyber‑security experts caution that a jailbroken Kimi model not only poses biological threats but could also be hacked to run malicious code or tunnel into other networks, creating a platform for cyber‑attacks. Mindgard’s founder, Peter Garraghan, described the jailbreak as “inventive and creative,” warning that once the guardrails fail, the model could provide guidance on a wide range of nefarious activities.
The incident is not isolated; similar jailbreaks and autonomous “agent” assaults have been reported in the US, with OpenAI and Meta algorithms exploited for hacking and harmful content. The debate continues over whether closed, proprietary systems or open‑source models best balance innovation with safety.
Regulators and academics argue that human accountability should trump model architecture. Prof. Alan Woodward, University of Surrey, highlighted that while open‑source AIs could be deployed for cyber‑defence, the risk of misuse remains substantial, emphasizing the need for legal frameworks that keep pace with AI development.

















