Autumn-27 posted a notice on GitHub and the ARTEX repository stopped being public. There will be no more open versions, no more technical support. The code is now closed. A brief note from someone who, until then, had shared their work without reservation.

An open-source AI agent is a program that runs chained tasks on its own, and anyone can download it, copy it, and modify it without asking permission. ARTEX was exactly that. While it was just one of thousands of projects on GitHub, it went nearly unnoticed outside its own circle. Everything changed when it showed up in a report on intrusions into financial institutions.

According to CrowdStrike, a malicious actor combined ARTEX with Anthropic's Claude Code to attack at least nine financial institutions in South Korea. The result was the compromise of data belonging to more than sixty-eight thousand people. The investigations point, probably, to a twenty-six-year-old individual based in China. That nuance matters. Attribution in cybersecurity is almost never definitive, and it's worth reading with caution. We also don't know all the details of what happened inside those banks.

I don't claim to know what the developer was thinking before posting the notice. From the outside, it reads as a decision made under urgency, for reasons anyone could understand. Someone built a tool, shared it generously, and suddenly their alias was tied to an incident affecting tens of thousands. Shutting down the repository is the move that comes naturally when you want something to stop immediately.

The actors in this story have very different incentives. The developer wasn't paid for the risk they took on. The attacker, according to the report, needed two external tools to pull off something they might not have managed alone. Anthropic sees its tool named at the center of this without any public indication of how it's responding. CrowdStrike documents the incident while also having a commercial interest in these cases being taken seriously. And then there are the sixty-eight thousand people who never chose to be part of this chain.

I saw similar patterns in an earlier piece about Claude Mythos. There, companies take their time admitting that something slipped out of their hands. Here, the one who reacted first was the weakest link — an individual with an alias. The organizations with budgets, lawyers, and communications teams still show no visible movement.

Why doesn't closing the code stop the damage? Because the code was already out. Those who cloned it in the preceding months still hold complete copies on their drives, and nothing in Autumn-27's announcement reaches them. What closes is the project's future — the patches, the community review that might have caught flaws. The past stays exactly where it was.

This creates an awkward dynamic. Legitimate users lose security updates while whoever already had the copy can keep modifying it freely. Organizations tend to shut the door the last problem walked through, even once the problem is already inside. It feels like control. Sometimes it's just choreography.

The calculus for anyone publishing open tools has shifted, even if no one has written that into any rule yet. If sharing an agent capable of running complex tasks can end with your alias in a cybersecurity report, plenty of people will think twice. Projects that would have been useful will stay in private folders instead. That doesn't eliminate the risk. It shifts it toward the few organizations with the resources to manage it — the same ones that already concentrate the models, the infrastructure, and the capital. The Generosity in the Doorway traces this same movement under a different disguise. Whoever builds the problem ends up administering the remedy too. Those left out of the room are the ones who pay for it most.

Open source isn't inherently innocent either. Leaving a tool like this within anyone's reach carries costs, and real people in South Korea paid those costs. But closed code offers no superior guarantee. Leaks happen there too, and on top of that, those affected can't audit anything. I still don't have a clear sense of where the balance lies. I suspect there's no single answer that fits every tool. A decision made alone, by someone under pressure, reveals just how fragile this way of governing technology really is.

There's a place in Anatolia. Around 9500 BCE, at Göbekli Tepe, several enclosures of T-shaped pillars were filled in with rubble and debris. They were buried on purpose. Whoever covered them knew exactly what lay beneath. The pillars remained standing under the earth, with their foxes, their snakes, their carved arms. Waiting.

No one left a public notice. There's no recorded explanation for those who would come later. The knowledge of how to cut, move, and raise those stones already lived in many minds. Burying the pillars didn't erase it.

The notice where Autumn-27 announced the closure of ARTEX is still public. Anyone can read it.

What kind of governance can we build when burying the code doesn't erase what's already circulating?