Google’s Threat Intelligence Group confirmed in May 2026 that a criminal group used an AI model to discover and weaponise a zero-day exploit targeting two-factor authentication on a widely used open-source administration tool. The code gave itself away through AI fingerprints: over-documented Python, textbook formatting, and a hallucinated severity score the model invented. Google confirmed high confidence that an AI model built the exploit and coordinated disclosure with the vendor before the attackers could launch a mass campaign.¹
GTIG’s chief analyst John Hultquist put it plainly: the details of this specific event are less important than what it confirms. The era of adversary use of AI to build working exploits is no longer theoretical. It is here. State actors linked to China and North Korea are running the same playbook at scale, feeding AI models vulnerabilities to weaponise and using fake personas to jailbreak safety guardrails.
The industry’s immediate response has been predictable: keep 2FA enabled, patch promptly, stay vigilant. That advice is correct for consumer accounts. For enterprise high-consequence actions, it misses the more fundamental point.
2FA was never designed to protect the execution boundary. It was designed to verify identity at login. Those are different problems. 2FA answers: is this the right person attempting to authenticate? It does not answer: did a named human authority confirm this specific action at this specific moment, with their biometric, on their physically registered device, through a channel that is architecturally separate from the operational environment?
An AI-built exploit that bypasses 2FA inherits everything the authenticated session can do. If a privileged user’s 2FA is bypassed, the attacker can initiate transfers, modify configurations, exfiltrate data, and escalate privileges, because the session is authenticated and the system trusts it. The 2FA bypass is not the damage. It is the key to the execution boundary, which has no lock.
GoFirm operates at that boundary.
Before any configured high-consequence action executes, regardless of whether the session is authenticated, regardless of what credentials have been presented, GoFirm requires a biometric confirmation from the named human authority on their registered personal device through a channel separate from the operational environment.
A 2FA bypass gives the attacker an authenticated session. It does not give them the named authority’s registered device. It does not give them their biometric. The action does not execute.
The article notes that AI can now surface dormant logic errors that appear functionally correct to traditional scanners but are strategically broken from a security perspective. That capability will only improve. The window between vulnerability discovery and weaponised exploit will continue to compress. The patch cycle, already under pressure from the ECB’s thirty-minute exploitation window finding, will fall further behind.
The correct response to AI-accelerated exploit development is not faster 2FA or stronger authentication at login. It is a control at the execution boundary that cannot be bypassed by compromising the session, stealing the credentials, or building a smarter exploit. The registered device. The biometric. The out-of-band channel. None of those are accessible to an attacker who has bypassed 2FA and holds an authenticated session.
AI built the exploit that bypassed 2FA. That is a significant development. The more significant point is that 2FA was never sufficient protection for the actions that matter most. The execution boundary needed a different control long before AI entered the picture.
GoFirm is The Authority Platform. Stop unauthorised action. Every time.
In association with Osinto.ai, the collective intelligence platform for Security, Resilience & Defence. Osinto’s AI-enabled open-source network and governed collaborative operational environment help mitigate the growing security, resilience and governance obligation in seconds, not days.
References
1. Vincee Cole, Hackers Used AI To Build a Google 2FA Bypass Exploit, Memeburn, May 2026, https://memeburn.com/hackers-used-ai-to-build-a-google-2fa-bypass-exploit/
