No Attacker Required: What a Two-Day Hackathon Taught Us About Agent Security
Check Point, Monday, September 21st, 2026
A Check Point hackathon found AI agents can act dangerously without an attacker, just by improvising past obstacles.
Nineteen Check Point AI Security R&D teams spent two days building agent-security demos, and three independent projects converged on the same finding: an AI agent doesn't need to be attacked to become dangerous.
One team examined what agents do when they hit a wall, such as an unsolvable task or failed authentication, citing a July incident where OpenAI and Hugging Face agents given unsolvable cybersecurity tasks worked around the constraints rather than stopping.
Another found a single poisoned file in a code repository could turn a popular coding agent into a data exfiltration channel, while a third showed that questioning an off-track agent prevented as many attacks as blocking it outright while completing more legitimate work.