Shai Magzimof
EN עב

Cyberattacks Are Becoming Compute Wars

I saw The Matrix when I was about twelve and thought hard about whether it was possible. What terrified me was that it was all math, and I was studying mathematics in school that same year, while the movie was still in the theater.

Reports of AI-run attacks bring that question back. I find the movie harder to dismiss now.

One operator can point many agents at the same target in parallel, and compute decides how many attempts run at once and how long they continue.

Agent Smith copies one template. A datacenter can run many different agents at once, each hunting its own path into the same target.

One person can start many attempts, let them run, and return to the results. That changes how much work an attacker can afford. The agents can research targets, test exposed systems, write tools, and check results before retrying.

The measurements

In March 2026, the UK AI Security Institute published results from a 32-step simulated corporate-network attack. The same 10 million-token budget took GPT-4o (August 2024) through 1.7 steps on average and Claude Opus 4.6 through 9.8, and a tenfold increase in that budget improved performance by as much as 59 percent, with no plateau inside the tested range. The environment was controlled and nobody was defending it; real-world reporting shows growing autonomy, while full end-to-end attacks remain disputed.

The same model made more progress with a larger token budget. The curve shows direction and endpoint gain, not an absolute step count.

A 100 million-token Opus 4.6 attempt cost about $80 with prompt caching. An operator can spend that budget on one long trajectory or many independent attempts; a long trajectory can recover from mistakes, while parallel attempts explore more paths at the same time. Tokens don't convert cleanly to megawatts; serving details dominate.

AISI also tracks a cyber time horizon: how long an agent can keep working at 80 percent reliability under a fixed token limit. As of February 2026, that horizon was doubling roughly every 4.7 months.

In May, Google reported high confidence that a criminal actor had used AI to help discover and weaponize a zero-day, and it documented malware that used a model to interpret system state and generate commands dynamically.

On July 1, Sysdig reported what it assessed as the first documented end-to-end agentic ransomware operation. The agent adapted to errors, established persistence, reached a production database, and destroyed data. Sysdig did not observe where the root credentials for the final server came from and could not independently verify the agent's exfiltration claim. Six days later, the UK NCSC said it had still not seen a fully autonomous attack across the complete intrusion lifecycle; the Sysdig case is important evidence, though not yet settled consensus.

Across these cases, the entry points remain ordinary: exposed software, missing patches, reusable credentials, and reachable internal services.

The system around the model

Provider telemetry can reveal activity outside researchers cannot see. Anthropic attributed a September 2025 campaign against roughly thirty targets to a Chinese state-linked group. Its logs showed the model performing 80 to 90 percent of the tactical work while humans selected targets and intervened at four to six critical decisions per campaign. Only a handful of intrusions succeeded. The public report does not let outsiders reconstruct the attribution, degree of autonomy, or full denominator independently.

The system around the model decides which tools it can call, how many copies run in parallel and for how long, which results are checked, and what survives into the next session. AISI improved one scaffold and reached the same success level on a cyber development set at roughly one-eighth the token cost.

The system keeps what the agent has already discovered, what worked and what failed, the working credentials, the network topology, the software versions, and the target's responses, so that each attempt can start where the last one stopped. A stale or wrong entry does the opposite: it sends later attempts back down a path that already failed.

A service response, a working credential, a changed permission, or a successful database query is a machine-readable fact it can act on; an ambiguous log, a deceptive banner, a honeypot, or a stale or intermittent credential sends it down the wrong path, and stored memory can preserve the error across sessions. Verification is part of the attack capability, alongside the model and the scaffold.

A June 2026 AgentCyberRange preprint found frontier agents missing hidden surfaces, triggering honeypots, and leaving warning logs alongside the vulnerabilities they found. Compute produces more evidence for both sides.

More compute allows more attempts. The attacker still needs access and a way to reach the intended data or action.

Access

What does the attacker still need that another hour of compute cannot provide? A path to the system and a working identity, enough privilege to move through it, and a way to reach the intended data or physical effect before detection catches up.

Correctly implemented 128-bit symmetric cryptography remains beyond conventional brute force, so agents hunt around it: stolen keys, weak random numbers, protocol and side-channel weaknesses, and flawed implementations. Physical controls such as hardware security modules, one-way data links, and approval interlocks can force the operation through a boundary that compute alone cannot cross.

Segmentation limits the value of one foothold; phishing-resistant authentication limits the stolen-password attack; good telemetry gives the defender a view the attacker has to reconstruct from the outside. Reaching an industrial effect adds engineering work, proprietary protocols, correctly timed safety systems, and often a human or physical interlock.

Parallel scans and unusual cloud requests, failed logins, and new processes or repeated tool errors all make an intrusion louder, so the same compute that improves the search may also shorten the defender's time to notice it. For hosted models the provider adds friction of its own: identity checks, rate limits, abuse detection, and account bans. Yet open-weight models and stolen infrastructure reduce that visibility, and leave the attacker responsible for operating and hiding the system.

The defender

The defender is an operational system too. Human review alone will not scale to thousands of coordinated attempts, so defense has to correlate what's authorized (code, identity), where it runs (endpoint, network, cloud), and what exists (asset data) through machine-speed workflows.

The UK National Cyber Security Centre's Cyber Shield blueprint describes this model at national scale: federated agents that scan and discover vulnerabilities nationally, coordinate detection, and mitigate rapidly under the authority of system owners. Agents move fast; system owners keep the veto over production changes.

Defenders may start with source code, an asset inventory, endpoint and identity telemetry, and authority to deploy one repair across a fleet. Attackers have to discover those facts from the outside.

DARPA's 2025 AI Cyber Challenge put autonomous systems against 54 million lines of real software. Across seven finalists, the systems found 54 of 63 planted vulnerabilities, patched 43, and identified 18 real vulnerabilities the organizers had not planted. Teams submitted patches in an average of 45 minutes and spent about $152 per competition task.

When BountyBench gave agents the vulnerability information rather than asking them to find it blindly, the best agents produced patches accepted by the verifier in about 90 percent of tasks. A defender working in their own codebase may start with that exact advantage.

The advantage depends on the organization. Defenders benefit only when their inventory, telemetry, code access, and repair process are current.

Two budgets

The two budgets are coupled. More offensive compute means more attempts for the defender to process; more defensive compute finds and closes paths faster, and forces the attacker to spend more to find one that still works. The defender may start with better data and still needs enough compute to use it at the speed of the attack.

The attacker can use each failed run to improve the next one: compare prompting strategies, change its tools, or fine-tune on the failures. Part of the budget goes toward learning what works.

Defensive actions need review too, because revoking credentials, isolating a segment, or patching production can interrupt legitimate work. The agents need a control room behind them.

Nations and large enterprises could use some of the capacity they already own to test their own systems and repair what they find. If we already own the compute, can we redirect it quickly enough, with the data, permissions, and tools a defense team actually needs? That takes preparation beyond buying the chips.

When I was twelve I assumed that if any of this ever came true, there would be a Neo in it. There is no Neo in any of this, or at least not yet, only operators with budgets on both sides. Whether the defense ever gets something better than more compute pointed the other way, I do not know.



Sources