Seller Posts Mistral AI Code Claiming Second Hack; Company Says No Fresh Breach Detected
A seller on a digital marketplace has uploaded what it claims to be the full source code of Mistral AI, alleging that the firm experienced a further security breach following the high‑profile incident reported in May 2026. The advertised files closely mirror the code snippets released in that earlier event, reigniting attention on the French AI startup.
Mistral AI answered swiftly, saying an internal audit uncovered no indication of a new unauthorized entry into its infrastructure. The firm highlighted that the probe, carried out by its security personnel together with outside auditors, revealed no evidence that the offered code is genuine or that any client data has been exposed.
The May 2026 intrusion, which resulted in part of Mistral’s proprietary models and training datasets being posted online, raised alarm throughout the artificial‑intelligence community regarding the robustness of up‑and‑coming AI companies. Mistral later reported that the perpetrators breached a small number of development repositories while insisting that primary production systems and customer information were left intact.
Analysts point out that this new allegation of a second breach, despite lacking solid evidence, may undermine trust among investors and collaborators already cautious about supply‑chain vulnerabilities in AI development. The resemblance between the code now on offer and the material leaked in May hints either at reuse of the same compromised assets or at opportunistic actors trying to cash in on the lingering fame of the prior leak.
Security specialists warn that not detecting an intrusion does not automatically eliminate the possibility of undisclosed data exfiltration, particularly when advanced threat groups use covert methods. They advise firms employing Mistral’s models to perform independent assessments and keep watch for any irregular activity that might signal tampering.
Going forward, Mistral has vowed to keep probing the matter and to work with law‑enforcement authorities if any illicit activity is substantiated. The firm also said it will strengthen its security stance, adding tighter access controls and broader monitoring to lessen the chance of future breaches. Until conclusive proof appears, the legitimacy of the code being sold cannot be confirmed, and the incident highlights the persistent difficulty of safeguarding AI intellectual property in a fast‑growing market.
Comments (0)
Be the first to comment.
Join the discussion