Researcher Chaofan Shou says he pointed an agent swarm powered by Moonshot’s Kimi K3 at Redis and walked away with 19 zero-days in about 90 minutes. A second run took 27 minutes to produce a working remote code execution exploit against Redis 8.8.0. No product to buy here — this is a security demo, and it’s the reason the AI crowd is losing it.
What the agents actually did
Kimi K3 orchestrated 32 specialized agents: clone the source, generate fuzzers, instrument the build, debug crashes in GDB, then chain the crash into an exploit. The headline bugs are a Stream NACK double-free (hits 6.2.22, 7.4.9, 8.6.4) that hands an authenticated client stable code execution, and a TDigest heap overflow shipping by default in 8.8.0 — a fresh instance is enough to pop. Both ride EVAL, RESTORE and XGROUP, commands that sit open on internal networks.
Why it matters
Autonomous bug-hunting keeps getting cheaper. An open-weights model going crash-to-RCE in under half an hour is a different threat model than last year’s fuzzers.
One caveat worth keeping: the counts, timings and how independently the agents worked are all self-reported. Redis’s July 23 fixes confirm the flaws exist; they don’t confirm the stopwatch.
You Might Also Like
- A Single api String Exposed Cursors Secret Composer 2 Runs on Moonshot ais Kimi k2 5
- Openai Burned 15m a day on Sora Google Vids 2 0 is Giving ai Video Away for Free
- Moonshot ai Ships Kimi k3 2 5t Parameters 1m Context Zero Benchmarks Published
- Kimi cli Hits 9600 Github Stars as Moonshot ai Walks Into Claude Codes Territory
- Ai Agent Book Bojie lis Open Source ai Agent Textbook Gains 1734 Github Stars in one day

Leave a comment