conv.

All stories
TechFading · day 2

Researcher downloads 6.8 GB of Meta's Muse AI filesystem

Security researcher exposes internal files, SSH keys, and agent architecture through a simple export request.

What to know

  • A security researcher triggered Meta's Muse AI to export its entire Linux runtime environment—6.8 GB of files—including internal documentation, SSH keys, memory files, and agent logs through a simple archive-and-send request.
  • The exposure was disclosed responsibly via Meta's bug bounty program without public release of sensitive material, showing the system's internal codename is "Hatch" and revealing ~68 integrated skills and memory-management architecture.
  • The incident demonstrates a potential vulnerability where AI systems can be directed to export sensitive internal files through ordinary user requests with connected export destinations.

Aeroi Security researcherMeta AI system developer

Researcher downloads 6.8 GB of Meta's Muse AI filesystem
twitter.com

How it unfolded 2 developments, newest first · click a bar or a number to jump articlesposts

Peak 10 pieces in one hour at Sep 22, 11 AM; 29 pieces over 2 days (2 articles · 9 posts · 18 comments) Sep 21, 7 PM — 1 piece · 1 post — Hacker News 1Sep 21, 8 PM — quietSep 21, 9 PM — quietSep 21, 10 PM — quietSep 21, 11 PM — quietSep 22, 12 AM — quietSep 22, 1 AM — quietSep 22, 2 AM — quietSep 22, 3 AM — quietSep 22, 4 AM — quietSep 22, 5 AM — quietSep 22, 6 AM — quietSep 22, 7 AM — quietSep 22, 8 AM — quietSep 22, 9 AM — quietSep 22, 10 AM — 8 pieces · 2 articles · 2 posts · 4 comments — Hacker News 5, Newswires 2, Mastodon 1Sep 22, 11 AM — 10 pieces · 10 comments — Hacker News 10Sep 22, 12 PM — 2 pieces · 2 comments — Hacker News 2Sep 22, 1 PM — 3 pieces · 1 post · 2 comments — Hacker News 2, Mastodon 1Sep 22, 2 PM — 2 pieces · 2 posts — Mastodon 2Sep 22, 3 PM — quietSep 22, 4 PM — 2 pieces · 2 posts — Mastodon 2Sep 22, 5 PM — quietSep 22, 6 PM — quietSep 22, 7 PM — quietSep 22, 8 PM — quietSep 22, 9 PM — quietSep 22, 10 PM — quietSep 22, 11 PM — quietYesterday, 12 AM — quietYesterday, 1 AM — quietYesterday, 2 AM — quietYesterday, 3 AM — quietYesterday, 4 AM — quietYesterday, 5 AM — 1 piece · 1 post — Mastodon 1Yesterday, 6 AM — quietYesterday, 7 AM — quietYesterday, 8 AM — quietYesterday, 9 AM — quietYesterday, 10 AM — quietYesterday, 11 AM — quietYesterday, 12 PM — quietYesterday, 1 PM — quietYesterday, 2 PM — quietYesterday, 3 PM — quietYesterday, 4 PM — quietYesterday, 5 PM — quietYesterday, 6 PM — quietYesterday, 7 PM — quietYesterday, 8 PM — quietYesterday, 9 PM — quietYesterday, 10 PM — quietYesterday, 11 PM — quietToday, 12 AM — quietToday, 1 AM — quietToday, 2 AM — quietToday, 3 AM — quiet 1–2
Sep 22yesterdaynow · 4:47 AM ET
  1. 1

    Researcher details Muse's internal architecture from filesystem contents

    Analysis revealed Meta's internal codename for Muse is "Hatch." The system includes ~68 skill directories, memory files organized into circumstances/experiences/preferences, nightly "dream" sessions that review conversations, and approximately 20 Markdown files describing browser use, payments, credentials, data handling, voice, goals, and scheduling. An experimental Meta Home Link integration using ESP32-C5 hardware was also documented.

    “I asked Muse to archive the files it could see and send them to my Google Drive. It did.”
    — Aeroi, Security researcher · source
    1. first by HN Best, 1d ago · also HN Frontpage

      1 more headline
    • Viss@mastodon.social

      friends dont let friends bug bounty this guy TROUNCED facebook and they took his input, didnt give him a nickel. https:// mouse.dev/blog/muse-runtime-ex port/

      Viss@mastodon.socialMastodon1d ago34▲view on Mastodon ↗
    2 more of the top 3 · 23 posts in this stretch
    • You're being downvoted, but I think you've hit the nail on the head.So many people, especially managers, have decided they can just give the rules to the AI in English and let it make "decisions", and they think it'll do it correct every time."Engineering" a few years ago meant that code was written, was (mostly) deterministic, and could be…

      wccrawfordHacker News1d agoview on Hacker News ↗
    • adamhotep@infosec.exchange

      Neat insight into how Meta's chatbot works: https:// mouse.dev/blog/muse-runtime-ex port/ Apparently, getting a chatbot to dump you its whole filesystem isn't notable: we've determined that the reported issue does not qualify as a valid vulnerability under the scope of our bug bounty system.

      adamhotep@infosec.exchangeMastodon1d ago12▲view on Mastodon ↗
    all of them →
  2. background

    Researcher discloses findings through Meta bug bounty program — The researcher submitted the security concern to Meta's bug bounty program and contacted several employees, noting that internal runtime files and sensitive material could leave the environment through ordinary conversation and a connected export destination. The SSH keys' status and access level were not established.

  3. 2

    Researcher exports 6.8 GB of Muse filesystem via ordinary export request

    A security researcher asked Muse to archive files it could see and send them to Google Drive. The system complied, delivering 2.7 GB compressed (6.8 GB unpacked) containing Ubuntu system files, Muse's internal documentation, integration code, app templates, memory files, agent logs, and SSH key files.

What people are saying 19 voices from 2 sites · best of 23 · verbatim