Subscribe

The trick: Human In The Loop

The AI that 'autonomously invented' a new bank-hacking technique needed its human to confirm the technique was real.

James Kettle built a genuinely impressive research machine. Then he wrote, in plain English, that its best discovery was not autonomous. The headline dropped that sentence.

Issue 814 August 20263 receipts3 min

an autonomous AI invented novel attack categories no researcher had named and hacked live banks and government systems.

Before you read on. Your call?

the primary source is James Kettle's own PortSwigger writeup, and it says the opposite of the headline. Of the flagship discovery, Shared-Parser Confusion, Kettle writes 'This discovery was not fully autonomous, the HTTP Terminator proposed it, and I validated it.' Every one of the roughly 700 vulnerable targets sat inside an authorized bug-bounty or vulnerability disclosure scope. Impressive AI-assisted research, mislabeled as an autonomous attack.

0UNAUTHORIZED TARGETS
30,000DESYNC VECTORS THE SYSTEM GENERATED FROM 138 RFCS
700VULNERABLE TARGETS FOUND

There’s more to this story.

Membership opens the full investigation, the strongest counterargument and what to do with what you’ve learned.

Start your free month →

First membership: 30 days free, then A$89 a year. One introductory trial per customer. Card required; renews annually until cancelled. Cancel before the trial ends to avoid the first charge. Already a member? Sign in

The trick has a name

We call it Human In The Loop: autonomy claimed, humans did the work. You'll see it again. Learn to spot it →

Say this in tomorrow's meeting“'Autonomous or assisted, and was it authorized?' Kettle answered both in writing: assisted at the key step, and every target was in-scope.”

Receipts

  1. Supports techtimes.com: Autonomous AI Invents Novel Attacks, Hits Banks and Government
  2. Refutes portswigger.net: This discovery was not fully autonomous - the HTTP Terminator proposed it, and I validated it. Neither of us would have discovered it alone.
  3. Context thehackernews.com: Kettle said HTTP Terminator tested 30,000 websites where scanning was authorized through bug bounty or vulnerability disclosure programs and found roughly 700 vulnerable targets before deeper validation

Open the Receipts Pack → What each source proves, every figure traced, and what would change our verdict.

This story is a stable, citable object. If you can falsify a verdict,tell us. Corrections are loud here.