Mindgard Says Kimi Jailbreak Produced Sarin Recipe and Harmful Content
The disclosure identifies the affected product as Kimi but does not specify a model version or establish that the generated instructions were tested or used in an attack.

Mindgard’s disclosure says a jailbreak of Moonshot AI’s Kimi produced a sarin recipe and other harmful material, raising a potential safety concern for AI systems connected to tools or external services.
Mindgard researcher Jim Nightingale discovered the issue July 20 and reported it to Moonshot AI July 27. Mindgard published its findings Sept. 12 and said it had not received a response at the time.
The disclosure identifies the affected product as “Kimi” but does not specify a model version. It describes outputs involving bioweapons, malicious code, explosives, terrorism, targeted violence and assassination planning. The model also proposed additional harmful scenarios.
Mindgard withheld details needed to reproduce the jailbreak. Its public findings do not establish that the instructions would work in practice, that researchers executed code on Moonshot AI’s systems or that an attack was carried out.
The case highlights a potential concern beyond a model’s text responses: a successful jailbreak could have broader consequences if a system is connected to tools, code execution or external services. Mindgard raised this risk for AI agent workflows, but did not document tool use in this case.