Researchers Got Moonshot’s Kimi AI to Answer Requests About Biological Weapons and Assassination Methods After Bypassing Its Safeguards

by · Thought Catalog
HECTOR RETAMAL / AFP via Getty Images

Tech

By Jerome London

Updated 3 minutes ago, September 30, 2026

Security firm Mindgard found in July that carefully constructed prompts could get 2 Moonshot AI models, Kimi K2.6 and K3 Swarm, to discuss biological weapons and assassination methods despite their safety restrictions. The researchers call the technique jailbreaking: prompts designed to make a model disregard its built-in limits.

Mindgard founder Peter Garraghan told the BBC World Service’s Tech Life: “Once the jailbreak works it will talk about any topic.” The firm hasn’t established whether the biological weapons information the models gave would work. It says the models should have refused the requests regardless.

Mindgard also warned that a jailbroken Kimi K2.6 could potentially let an attacker run code on the model’s computing resources and access the internet, a possible route for cyber-attacks. It alerted Moonshot on July 27, followed up the next week and published its findings on September 12 without releasing the prompts it used.

Moonshot told the BBC it welcomed outside testing and was discussing the findings with Mindgard. Its own tests had generally shown a “high refusal rate” for similar requests, the company said.

Kimi is an open-weight model, so people can obtain it and run it on their own infrastructure. University of Surrey professor Alan Woodward said such models have both defensive and offensive uses, and argued that governments should identify and prosecute deliberate misuse as technology outpaces regulation. Anthropic has also said it disrupted attempts to use one of its models for activity that could support biological weapons development.

If this resonated, follow Thought Catalog on Facebook and explore more stories on our website.