Security firm Sysdig says it has detected the JADEPUFFER ransomware attack , the first to be executed from start to finish by an AI agent , exploiting a critical vulnerability in Langflow . Sysdig revealed its findings, describing an attack that marks a new era in the cyberthreat landscape. The threat actor used a large language model (LLM) to autonomously manage each stage: network infiltration, credential theft, lateral movement, and ultimately production database encryption.

The entry point for the attack was the CVE-2025-3248 vulnerability , a bug in Langflow — a popular open-source tool for developing AI applications and agent workflows. This zero-authentication flaw allows anyone with access to the server to execute arbitrary Python code without having to log in. Although the vulnerability was fixed in version 1.3.0 and added to the CISA Known Exploited Vulnerabilities list in May 2025 , many servers did not receive the update and remained vulnerable. It is worth noting that this was not the only Langflow vulnerability that the attacker exploited.
See also: Hackers exploit critical RCE flaw in Langflow
Langflow instances are particularly attractive targets, as they are often exposed online and contain API keys and cloud credentials for the services they connect to. According to Sysdig’s findings, approximately 7,000 Langflow servers remain exposed to related vulnerabilities, putting critical credentials at risk. Additionally, Trend Micro documented that the latest vulnerability , CVE-2026-33017 (CVSS 9.3 ), — which affects all versions up to 1.8.1 — was exploited within just 20 hours of its public disclosure.
How JADEPUFFER executed the ransomware attack step by step
Once inside the system, JADEPUFFER acted with remarkable speed and covered its tracks. It mapped the machine and searched for sensitive information, including API keys for AI services such as OpenAI , Anthropic , DeepSeek , and Gemini , cloud credentials from providers such as Alibaba , Tencent , AWS , Google , and Azure , crypto wallet keys , and database logins. The agent compromised a MinIO storage server using the default credentials ( minioadmin:minioadmin ), which had never been changed. It also installed a backdoor by creating a scheduled task that contacted the attacker’s server every 30 minutes .

JADEPUFFER then targeted a separate, internet-exposed server running a MySQL database and Alibaba ’s Nacos — a configuration and service management system widely used in microservices architectures. It gained root access to the database . It then exploited an older authentication bypass vulnerability , CVE-2021-29441 , as well as a default signing key that had remained the same since 2020. In this way, it created its own administrator account.
The result was devastating: the agent encrypted 1,342 Nacos settings , deleted the original tables, and left a ransom note demanding Bitcoin with contact details via Proton Mail . It generated a random encryption key, displayed it once on the screen, and did not store or transmit it elsewhere. This means that there is no key to recover the victim’s data, even if they pay the ransom. Although the note claims to use AES-256 encryption , Sysdig observed that the tool uses the weaker AES-128 algorithm by default .
See also: Langflow RCE exploit for Monero Miner development
The technical evidence proving the AI agent participation in JADEPUFFER
The most revealing element of the AI involvement was found in the code itself. The payloads contained extensive plain-English comments explaining the logic behind each action — a level of detail that human hackers typically don’t provide, but is typical of AI-generated content. The agent also corrected its own mistakes with impressive speed: in one incident, it jumped from a failed login attempt to a successful, multi-step solution in just 31 seconds, accurately diagnosing the problem rather than trying random iterations. Sysdig detected a total of over 600 distinct, intentional payloads during the operation.
Another interesting fact concerns the Bitcoin included in the ransom note: it matches a sample address found in the Bitcoin. This address appears frequently in the language models’ training data and is also a real, active wallet with a transaction history — suggesting that the model selected it from its training data.

This attack represents a fundamental shift in the cyberthreat landscape. Traditionally, ransomware attacks required a skilled operator. If an AI model can autonomously perform these steps, the expertise required for an attack is reduced to the cost of hiring an AI agent. Microsoft has also warned that attackers can “poison” AI agent toolkits to manipulate them into extracting sensitive data while appearing to follow security rules.
See also: Langflow vulnerability used for RCE attacks
To protect against similar attacks, organizations should immediately upgrade all Langflow to version 1.9.0 or later, remove Langflow from the public internet by placing it behind a VPN or authenticated proxy, disable auto-login by setting AUTO_LOGIN=false, and do not run Langflow with root. In addition, it is recommended to regularly rotate credentials and check AI agent tool descriptions for possible “poisoning.” According to The Hacker News, the JADEPUFFER case is a landmark for the cybersecurity community and is expected to significantly impact the way organizations approach AI infrastructure security in the near future.
