AI Just Made Your Bank's Database Cheaper to Rob
An unknown attacker using an open-source AI hacking tool went after South Korean banks and walked off with customer data. Every database holding your information is a honeypot, and probing one just got cheaper.

TFTC - Truth for the Commoner The Commoner | |||||||||||||||||||||||||||
Friday, October 9, 2026 | |||||||||||||||||||||||||||
Sup, freaks. Another week, another honeypot raided. This time it's South Korea's banks, and I'm afraid AI made the job a lot easier than it should have been. | |||||||||||||||||||||||||||
WHAT TO EXPECT IN THIS NEWSLETTER
| |||||||||||||||||||||||||||
Marty's Bent | |||||||||||||||||||||||||||
AI Just Made Your Bank's Database Cheaper to RobAnother week passes and yet another database stuffed with the intimate financial details of regular people has been ransacked. This time it's South Korea's banks. Shinhan Bank says the loan-application data of about 25,000 customers was taken: names, phone numbers, annual incomes, calculated loan limits and, for 66 unlucky souls, resident registration numbers, according to the Seoul Economic Daily. Reuters reports at least nine South Korean banks have disclosed or been reported as targets since late September, and AFP says the country's Financial Services Commission puts the number of people affected at more than 68,000. Your Uncle Marty has been banging this drum for years. Back in 2020, when Ledger's customer database leaked, I wrote that trusted third parties are security holes. It was true then and it's even more true today. Every company that collects your income, your ID number and your phone number is building a target and asking you to trust that they can defend it. KYC/AML policies push financial companies to collect and hoard more and more of this information in the name of stopping crime. Nothing I've seen shows a KYC rule caused this particular breach, but don't let that distract you from the bigger picture. These databases are honeypots, and the people forcing them into existence never seem to pay the price when they get raided. And now raiding them is getting cheaper. On Wednesday CrowdStrike published a report tying the campaign to an unknown threat actor using ARTEX, an open-source AI penetration testing tool developed in China. ARTEX ran on DeepSeek v4.1-flash, and the actor ran additional Claude Code sessions on GLM-5.3 and Grok 4.6. At Shinhan, the attacker reportedly got around the authentication on a mobile site loan brokers use to check on applications and "randomly entered inquiry values to obtain customer numbers and steal other data." Try every door until one opens. That is exactly the type of tedious grunt work you hand off to a machine. South Korea's president, Lee Jae Myung, said it plainly at a cabinet meeting this week: "We have now reached a point where AI can make [hacking] easy for even those without special skills." Whoever was behind this was no criminal mastermind. CrowdStrike found open directories the attacker left exposed on infrastructure they controlled, stuffed with Claude Code session histories, ARTEX configuration files and a CLAUDE.md file full of Chinese-language pentesting instructions. According to CrowdStrike, the attacker asked Claude where threat actors typically sell Korean breach data and how to find Korean Telegram data-sales groups. Then they asked it to write up a security-researcher résumé. You can't make this stuff up. CrowdStrike assesses with moderate confidence that the actor is a Chinese speaker and financially motivated, and it hasn't established who was behind the activity or how many people were involved. Whoever it was managed to leave their own files wide open while they were busy taking everyone else's. Anthropic announced a cyber defense program the next day and admitted as much: "The cost of exploiting vulnerabilities has dropped, while verifying, disclosing, and fixing them is slow and still depends on people." Great. Better defensive tools may help the banks holding your data. They can't put the Shinhan customers' stolen incomes and phone numbers back in the bank's hands. Yesterday we spent the whole rag arguing over whether AI could crack the math securing your bitcoin. Nobody had to break secp256k1 to get these records. They just had to get past the front of a loan-status page. And a scammer who knows your income, your loan limit and your phone number is going to have a much easier time convincing you he's calling from your bank. Hold your own keys, freaks, but don't confuse controlling your bitcoin with erasing the information an exchange already has on you. Hand over as little of yourself as you possibly can. And stop accepting the premise that more data collection makes anybody safer. It creates more honeypots for cheap AI agents to probe. Asking everyone to get better at spotting phishing calls while forcing them to keep forking over their personal information is an absurd response to this problem. End KYC/AML. It's time for better police work instead. | |||||||||||||||||||||||||||
SIGNAL | |||||||||||||||||||||||||||
BANKS Wells Fargo's bank shrank its workforce and paid out more than it earnedBill Moreland at BankRegData sent over another great Call Report breakdown, putting U.S. bank employment at 2,034,204 full-time equivalents in the second quarter, down 95,085 since early 2023. Those are depository-bank numbers. FDIC data show Wells Fargo Bank's full-time equivalents fell by 35,494 from early 2023 through mid-2026, 5,487 of them in that quarter alone. In the same quarter the bank paid $10 billion in dividends on $6.85 billion of net income. That's about 146% of earnings, with the difference coming out of capital. As Bill puts it, when big banks beg for "capital relief," "what they really mean is they want to pay out more dividends." He closes with BEA data on wages and salaries as a share of gross domestic income, which he shows sliding since the U.S. left the gold standard, and argues "tethering once again to sound money and enacting a balanced budget amendment would go a long way." Fix the money, fix the world. Analysis credited to Bill Moreland and BankRegData, used with permission. | |||||||||||||||||||||||||||
MARKETS Feeling sidelined? Read James CheckIf you feel like you missed the boat as bitcoin slid back toward $80,000, James Check wrote his latest Checkonchain letter for you. His point is that FOMO hurts more than taking a loss, and it drives the same dumb mistakes over and over: lump-summing at the local high, panic selling the next dip and waiting for a lower price that never comes. He leans on short-term holder SOPR, which shows whether recent buyers are selling at a profit or a loss. He reads a move below 1.0 as recent buyers capitulating, and those are the dips he wants to buy. Bitcoin Lab's reading in the snapshot below slipped to 0.995 on October 8. He expects a few months of chop between $72,000 and $100,000 and says a weekly close below $72,000 would prove his bullish bias wrong. His fix is simple. Run a DCA plan and stop trying to guess the next low. If every dip has you rethinking the whole plan, you're letting your emotions make the call. | |||||||||||||||||||||||||||
POLICY Government-linked bitcoin is moving. That doesn't prove a reserve saleGalaxy Research tracked about 9,261 BTC from U.S. government-linked wallets to Coinbase Prime on October 6 and 7, and on-chain analyst EmberCN says another 12,267 BTC from a Bitfinex hack-recovery address landed there Thursday. We haven't found an official explanation for these transfers, and a deposit isn't a sale. Galaxy also points out that 71% of the roughly 319,086 BTC it tracks to the government "sits in two buckets that are not settled government property: the LuBian coins and the Bitfinex recoveries." That matters because the March 2025 executive order capitalizes the Strategic Bitcoin Reserve with qualifying bitcoin from final forfeitures or civil money penalties, and says bitcoin deposited into the reserve "shall not be sold." It also allows returning coins to identifiable victims of crime. If these coins are headed back to Bitfinex, that's property rights working, not the government dumping its stack. Relax, freaks. | |||||||||||||||||||||||||||
ENERGY DOE to PJM: data centers pay their own wayThe Department of Energy filed a statement at FERC on October 7 urging PJM to move fast on cost-allocation reforms so the costs of serving new data centers "are not unfairly shifted to PJM's existing ratepayers." It says large loads, "not American households or other business ratepayers," must fund the generation and infrastructure they require. Utility Dive reports PJM now plans to file a revised proposal by October 29. Builders should pay for the power infrastructure their projects require. That gives residents a reason to welcome new capacity instead of dreading the next electric bill, which is a much better answer than the county moratoriums we covered yesterday. DOE is asking for that protection. PJM still has to propose the changes, and the voluntary pledge doesn't make them binding. | |||||||||||||||||||||||||||
SURVEILLANCE Towns are saying no to plate readersFayetteville, Arkansas' city council voted 7-0 on Tuesday to bar city money and property from being used on license plate reader systems. Its police department doesn't use them yet, so this one is preemptive, with an exception for a parking-enforcement reader whose data is generally deleted within 48 hours. In Connecticut, South Windsor's council voted 6-3 to end its Flock contract and pull the cameras within 60 days. Avon, Colorado voted 4-3 to terminate its Flock contract, and Lafayette, Colorado approved a first-reading budget with no Flock money, with a second reading October 20. Good. Fayetteville is choosing not to build this surveillance system in the first place, which beats collecting everyone's movements and asking residents to trust the records will never be abused or leaked. See the lead for how that tends to work out. | |||||||||||||||||||||||||||
| |||||||||||||||||||||||||||
| |||||||||||||||||||||||||||
⚡ FREEDOM TECH CORNER | |||||||||||||||||||||||||||
BTCPay Server limits public access to old receiptsBTCPay Server v2.4.5 hides checkout, status and receipt information from public endpoints one month after an invoice's monitoring ends, while users with invoice-view permission keep access. Your customers' payment details shouldn't sit on a public link indefinitely, and this update puts a limit on that exposure. Before upgrading, check whether your setup connects to private-network services, like a Lightning node on your local network. The release blocks private-network destinations by default for Lightning connections, LNURL requests, notification URLs and webhooks to prevent server-side request forgery, and those connections need to be allowed with the new ssrfexceptions setting. Review it as part of the upgrade so the privacy improvement doesn't come with a broken connection to your node. | |||||||||||||||||||||||||||
DATA SNAPSHOT | |||||||||||||||||||||||||||
Spot price, block height and hashrate estimate: October 9, 2026, 8:59 a.m. ET. Bitcoin Lab daily series: October 8, 2026. U.S. spot ETF flows: October 8, 2026. | |||||||||||||||||||||||||||
| |||||||||||||||||||||||||||
Sources: Kraken spot quote, mempool.space block height and hashrate, Bitcoin Lab daily metrics, and TFTC ETF flows. Daily metrics use the provider’s October 8 observation, not live intraday estimates. | |||||||||||||||||||||||||||
| |||||||||||||||||||||||||||
| |||||||||||||||||||||||||||
Have a great weekend, freaks. | |||||||||||||||||||||||||||
Marty Bent · TFTC · Nostr |


