Subscribe

The trick: Zero Underneath

The 'autonomous AI strike on a nuclear agency' was 85 cracked passwords at a personnel office.

Real attack, real agents, real loot. The nuclear part is a target list that got scanned, and the autonomy shipped with a human operator attached.

Issue 713 August 20263 receipts3 min

open-source AI agents ran a four-day autonomous strike that breached Taiwan's nuclear safety agency.

Before you read on. Your call?

Dream's own report confirms compromises at a government department (85 cracked accounts, 2,564+ personnel records) and lists the nuclear agency only as an expansion target the agents scanned. Dream itself writes 'what appears to be a near-autonomous attack', and Taiwan's digital ministry describes a hybrid operation combining conventional hacking with AI agents.

0CONFIRMED NUCLEAR-AGENCY COMPROMISES
85GOVERNMENT ACCOUNTS CRACKED
2,564PERSONNEL RECORDS EXFILTRATED

There’s more to this story.

Membership opens the full investigation, the strongest counterargument and what to do with what you’ve learned.

Start your free month →

First membership: 30 days free, then A$89 a year. One introductory trial per customer. Card required; renews annually until cancelled. Cancel before the trial ends to avoid the first charge. Already a member? Sign in

The trick has a name

We call it Zero Underneath: the headline number has nothing behind it. You'll see it again. Learn to spot it →

Say this in tomorrow's meeting“'Which systems at the nuclear agency were compromised, and who confirmed it?' If the answer is a target list, you are reading about a scan, not a breach.”

Receipts

  1. Supports dreamgroup.com: In roughly four days, the agentic attacker produced 1,395 files, 85 cracked credentials, thousands of exfiltrated personnel records, and gained a persistent foothold inside state infrastructure.
  2. Refutes focustaiwan.tw: the attacks showed clear signs of originating overseas and involved a hybrid approach combining conventional hacking with AI agents such as OpenClaw
  3. Context theregister.com: The agents also tested predictable password patterns based on each employee's ID, and cracked 85 accounts across multiple password-spray rounds.

Open the Receipts Pack → What each source proves, every figure traced, and what would change our verdict.

This story is a stable, citable object. If you can falsify a verdict,tell us. Corrections are loud here.