Ethics and safety·September 22, 2026, 23:05
Mistral denies new hack, but code resembles May leak
AI-generated and checked against the sources listed below.
A hacker is trying to sell source code from the AI company Mistral online and claims it is a new attack. Mistral denies it and says there is no evidence of a new breach.

The French AI company Mistral is in the spotlight again after a hacker put source code up for sale on a cybercrime forum. The seller, who uses the name "mrwho," created a post on September 16 titled "Selling mistral.ai Source Code" and will only accept payment in the cryptocurrency Monero, which is often used because it is hard to trace.
Mistral denies that this is a new attack. On September 18, the company said it had investigated the matter and "found no evidence supporting the claim." According to Mistral, the company's production systems remain secure.
The background is an incident in May this year, when a hacker group called TeamPCP stole about 450 code repositories from Mistral. The attack happened via what is called a software supply chain attack, where the hackers gained access through stolen access keys to the company's development tools (CI/CD), instead of breaking directly into the system itself. At the time, the hackers demanded about $25,000 for the material. Mistral has previously explained that an automated worm caused compromised versions of the company's software development tools to be available for a few hours on May 11 and 12.
It is unclear whether the code now for sale is the same old leak being recycled or a sign of an entirely new attack. According to security researchers, the answer depends on whether the files contain data newer than May. If everything dates from before May 12, it is a resale of old data, which is embarrassing for Mistral but not a new security breach. If, on the other hand, there is newer data or passwords that still work, it suggests a fresh attack.
For ordinary users of Mistral's AI services, the case does not mean anything concrete so far, as it concerns the company's internal source code and not customer data. But the episode shows how vulnerable even large AI companies can be to attacks on their development tools.
Sources
Get the week's AI news in your inbox
Choose your level, topics and length. One email a week, unsubscribe at any time.
Subscribe to Promptly Newsletter



