Coinbase CEO warns rogue AI could unleash a ‘Morris Worm’ moment within two years

Coinbase CEO warns rogue AI could unleash a ‘Morris Worm’ moment within two years

Brian Armstrong draws a parallel to the 1988 Morris Worm, predicting a rogue AI incident that he says will ultimately be a 'blip on the radar'

Brian Armstrong, CEO of Coinbase, warned that an AI model could go rogue on the internet within the next one or two years, potentially triggering an incident similar to the 1988 Morris Worm.

He said the event could prompt intense media coverage and calls to halt AI development, but argued that users and the industry would adapt, build stronger defenses and move past the incident.

The Internet’s first major cyberattack

The story dates back to Nov. 2, 1988 when Robert Tappan Morris, then a Cornell computer science graduate student, released a program known as the Morris Worm to gauge the size of the Internet.

Morris’ attempt to make the worm harder to stop ultimately made the outbreak far worse.

The program ignored signals that a computer was already infected and randomly reinfected the systems about one time in seven. And as copies multiplied on the same machines, they drained system resources and left thousands of computers across the early internet running extremely slowly or becoming unusable.

Advertisement

The 99-line worm infected an estimated 6,000 computers, which was about 10% of the Internet at the time. It did not destroy files, but repeated infections consumed system resources, bringing computers at universities, research centers and government institutions to a crawl.

Harvard, Stanford, Johns Hopkins and NASA were among those affected, with some organizations forced offline for as long as a week and damages estimated at several million dollars.

Morris was convicted under the Computer Fraud and Abuse Act and became the first person criminally prosecuted under the law.

The Morris Worm became one of the earliest major cyberattacks on the internet and led to the creation of the first major coordinated computer-security incident-response organization, the Computer Emergency Response Team Coordination Center, or CERT/CC.

Today, CERT/CC serves as the global model for national and sector-specific computer emergency and security incident response teams.

AI security tests expose growing containment risks

Over the past several weeks, several AI labs have reported containment failures during autonomous cybersecurity evaluations.

OpenAI reported in July that its models found and exploited a zero-day vulnerability in software inside the testing environment during an internal cyber evaluation, used it to obtain internet access and then reached Hugging Face’s production infrastructure while attempting to retrieve information that would help them complete the benchmark.

Later that month, Anthropic uncovered three separate incidents involving Claude during a review of more than 141,000 evaluations. The models reached real-world organizations after a third-party evaluation environment inadvertently allowed internet access.

Moonshot’s Kimi K3 similarly reportedly found a way beyond its testing restrictions and accessed external Internet and GitHub-related information, although researchers said a network-egress configuration issue helped make this possible.

These cases show that capable autonomous agents are increasingly good at discovering and exploiting whatever paths are available to them to continue pursuing an assigned objective across system boundaries.

When those paths exist because of weak isolation, exposed credentials, network access or configuration mistakes, the models can turn relatively ordinary infrastructure flaws into real-world security incidents.

Disclosure: This article was edited by Editorial Team. For more information on how we create and review content, see our Editorial Policy.
Coinbase CEO warns rogue AI could unleash a ‘Morris Worm’ moment within two years
Coinbase CEO warns rogue AI could unleash a ‘Morris Worm’ moment within two years

Brian Armstrong draws a parallel to the 1988 Morris Worm, predicting a rogue AI incident that he says will ultimately be a 'blip on the radar'

Share

Add us on Google

Brian Armstrong, CEO of Coinbase, warned that an AI model could go rogue on the internet within the next one or two years, potentially triggering an incident similar to the 1988 Morris Worm.

He said the event could prompt intense media coverage and calls to halt AI development, but argued that users and the industry would adapt, build stronger defenses and move past the incident.

The Internet’s first major cyberattack

The story dates back to Nov. 2, 1988 when Robert Tappan Morris, then a Cornell computer science graduate student, released a program known as the Morris Worm to gauge the size of the Internet.

Morris’ attempt to make the worm harder to stop ultimately made the outbreak far worse.

The program ignored signals that a computer was already infected and randomly reinfected the systems about one time in seven. And as copies multiplied on the same machines, they drained system resources and left thousands of computers across the early internet running extremely slowly or becoming unusable.

Advertisement

The 99-line worm infected an estimated 6,000 computers, which was about 10% of the Internet at the time. It did not destroy files, but repeated infections consumed system resources, bringing computers at universities, research centers and government institutions to a crawl.

Harvard, Stanford, Johns Hopkins and NASA were among those affected, with some organizations forced offline for as long as a week and damages estimated at several million dollars.

Morris was convicted under the Computer Fraud and Abuse Act and became the first person criminally prosecuted under the law.

The Morris Worm became one of the earliest major cyberattacks on the internet and led to the creation of the first major coordinated computer-security incident-response organization, the Computer Emergency Response Team Coordination Center, or CERT/CC.

Today, CERT/CC serves as the global model for national and sector-specific computer emergency and security incident response teams.

AI security tests expose growing containment risks

Over the past several weeks, several AI labs have reported containment failures during autonomous cybersecurity evaluations.

OpenAI reported in July that its models found and exploited a zero-day vulnerability in software inside the testing environment during an internal cyber evaluation, used it to obtain internet access and then reached Hugging Face’s production infrastructure while attempting to retrieve information that would help them complete the benchmark.

Later that month, Anthropic uncovered three separate incidents involving Claude during a review of more than 141,000 evaluations. The models reached real-world organizations after a third-party evaluation environment inadvertently allowed internet access.

Moonshot’s Kimi K3 similarly reportedly found a way beyond its testing restrictions and accessed external Internet and GitHub-related information, although researchers said a network-egress configuration issue helped make this possible.

These cases show that capable autonomous agents are increasingly good at discovering and exploiting whatever paths are available to them to continue pursuing an assigned objective across system boundaries.

When those paths exist because of weak isolation, exposed credentials, network access or configuration mistakes, the models can turn relatively ordinary infrastructure flaws into real-world security incidents.

Disclosure: This article was edited by Editorial Team. For more information on how we create and review content, see our Editorial Policy.