Close Menu
    X (Twitter) LinkedIn
    CapitalAI DailyCapitalAI Daily
    X (Twitter) LinkedIn
    • Markets & Investments
    • Big Tech & AI
    • Fraud & Scams
    • Hacks
    • Banks
    • Crypto
    Wednesday, September 24
    CapitalAI DailyCapitalAI Daily
    Home»Hacks»‘First Known’ AI-Powered Ransomware Emerges, Embeds Bitcoin Address Linked to BTC Creator Satoshi Nakamoto: Security Researchers
    ai-ransomware-bitcoin-satoshi

    ‘First Known’ AI-Powered Ransomware Emerges, Embeds Bitcoin Address Linked to BTC Creator Satoshi Nakamoto: Security Researchers

    By CapitalAI Daily TeamAugust 29, 20252 Mins Read
    Share
    Twitter LinkedIn

    A cybersecurity threat intelligence firm is warning that it has discovered the emergence of the first ransomware sample known to be powered by artificial intelligence (AI).

    In a new thread on X, Eset Research says it has uncovered PromptLock, a malware running OpenAI’s GPT-oss:20b model through the Ollama API.

    According to the security researchers, the malware generates Lua scripts that scan local files, exfiltrate data, and perform encryption across Windows, Linux, and macOS.

    “ESET Research has discovered the first known AI-powered ransomware, which we named PromptLock… Based on the detected user files, the malware may exfiltrate data, encrypt it, or potentially destroy it…

    For its file encryption mechanism, the PromptLock ransomware utilizes the SPECK 128-bit encryption algorithm.”

    In a notable twist, the ransomware’s prompts hard-code a Bitcoin address linked to Satoshi Nakamoto, the pseudonymous creator of Bitcoin.

    “Although the destruction functionality appears to be not yet implemented. Bitcoin address used in the prompt appears to belong to Bitcoin creator Satoshi Nakamoto.”

    While ESET does not provide more details on the relevance of Nakamoto’s address, it suggests that the malware is not yet fully operational, as the Bitcoin creator’s address has been inactive since the early days of BTC. Funds sent to that address will likely never be recovered.

    The firm echoes the view.

    “Although multiple indicators suggest the sample is a proof-of-concept (PoC) or work-in-progress rather than fully operational malware deployed in the wild, we believe it is our responsibility to inform the cybersecurity community about such developments.”

    AI-powered ransomware Bitcoin BTC GPT PromptLock ransomware

    Read More

    ARK Invest’s Cathie Wood Names AI Race ‘Big Four,’ Says Crypto Igniting Three Revolutions in One

    September 22, 2025

    Solana’s Anatoly Yakovenko Warns AI and Quantum Advances Could Break Bitcoin Cryptography – Here’s When

    September 19, 2025

    BlackRock CIO Rick Rieder Names Assets Powering ‘Best Investment Environment,’ With Opportunities Across Tech, Gold, and More

    September 10, 2025

    Hacker Lets Claude Code Orchestrate Full AI Cyberattack, With Ransom Demands Topping $500,000: Anthropic Report

    August 30, 2025

    Ransomware Gang Wields Generative AI To Target 113 Firms Worldwide, Warns Fortune 500 Cybersecurity Firm

    August 21, 2025
    X (Twitter) LinkedIn
    • About Us
    • Contact Us
    • Privacy Policy
    • Terms of Service
    • Opt-out preferences
    © 2025 CapitalAI Daily. All Rights Reserved.

    Type above and press Enter to search. Press Esc to cancel.