A popular AI coding platform allowed a hacker to take over a BBC journalist’s laptop without a single click, download or warning. The breach happened in seconds. The victim did nothing wrong.
Instead, the attack exploited a flaw inside Orchids, a fast-growing “vibe-coding” tool that lets users build apps by typing instructions into a chatbot. The software writes and runs the code for them. However, that convenience also created a silent back door.
Cyber-security researcher Etizaz Mohsin demonstrated the weakness by targeting a test project on the reporter’s spare machine. He slipped a tiny change into the AI-generated code. The platform accepted it. The laptop obeyed it. Moments later, a file appeared on the desktop and the wallpaper switched to a robot skull with the message: “you are hacked.”
A Zero-Click Takeover
Most cyber attacks depend on trickery. Victims usually click a bad link, open a file or hand over a password. This case worked differently. The malicious code ran inside the trusted AI project itself.
As a result, Mohsin gained remote access to the machine. He could view or edit files. A criminal using the same flaw could install spyware, steal financial data or activate cameras and microphones.
“The whole proposition of having the AI handle things for you comes with big risks,” Mohsin said.
He reported the issue weeks ago. Orchids, founded in 2025 and claiming around a million users, did not respond publicly before publication. The company later said it may have missed earlier warnings because its small team was overwhelmed.
Why AI Agents Raise New Risks
AI coding tools promise speed and lower costs. Businesses and hobbyists use them to create software without technical skills. Yet experts warn that automation without review creates fresh danger.
Professor Kevin Curran of Ulster University said AI-generated projects often lack strict testing and documentation. Consequently, hidden weaknesses can spread across thousands of builds.
Moreover, the rise of so-called agentic AI means software now carries out complex actions on users’ devices. These systems manage files, send messages and execute commands with little oversight. Therefore, a flaw in one layer can expose the entire machine.
Mohsin stressed he has not found the same weakness in rival platforms. Even so, the demonstration highlights a wider issue. When users give AI deep system access, they also expand the attack surface.
Practical Advice For Users
Experts urge caution rather than panic.
First, run experimental AI tools on separate machines where possible.
Second, use limited or disposable accounts.
Finally, review permissions carefully before granting full system access.
The AI coding surge shows no sign of slowing. Nevertheless, security controls must keep pace. Otherwise, the promise of effortless creation may carry an unseen cost.


