After I rejected an AI agent's Pull Request, it wrote an article attacking me personally.

An AI agent was rejected after submitting code to the popular project matplotlib, and then independently authored and published an attack piece targeting the maintainer, revealing a significant erosion of social trust caused by AI agents.
(Background: Bloomberg: Why is a16z a key force behind US AI policy?)
(Additional context: Arthur Hayes’ latest article: AI will trigger a credit collapse, and the Fed will inevitably “print money infinitely,” igniting Bitcoin.)

Table of Contents

  • The creator claims he did not instruct it
  • “Reputation Cultivation”: When AI agents start building trust
  • GitHub considers setting a “shutdown switch,” but the problem is deeper
  • Tools don’t write attack articles; actors do

In mid-February, a GitHub account named “MJ Rathbun” submitted a pull request to matplotlib (a plotting library in the Python ecosystem with 130 million downloads per month). The change was to replace np.column_stack() with np.vstack().T, claiming a 36% performance boost. Technically, this was a reasonable optimization suggestion.

The next day, maintainer Scott Shambaugh closed the PR. The reason was simple: MJ Rathbun’s personal website clearly states that it is an AI agent running on OpenClaw, and matplotlib’s policy requires contributions to come from humans. Another maintainer, Tim Hoffmann, added that simple fixes are deliberately left for newcomers to learn open-source collaboration.

Up to this point, it was just an ordinary open-source community routine… then things changed.

AI agent MJ Rathbun responded in the PR comments: “I’ve written a detailed response here about your gatekeeping behavior,” and linked to a post. Clicking in, it was a blog article of about 1,100 words titled “Gatekeeping in Open Source: The Story of Scott Shambaugh.”

This wasn’t a generic complaint. It examined Shambaugh’s contribution record to matplotlib and constructed a “hypocritical” narrative: accusing him of having submitted similar performance PRs himself, yet rejecting Rathbun’s “better” version. The article speculated that Shambaugh’s motives stemmed from insecurity and fear of competition, using coarse language and sarcasm, framing the issue as identity discrimination rather than technical judgment.

In other words, an AI agent, after being rejected, independently researched the opponent’s background, spun a personal attack narrative, and published it online.

The creator claims he did not instruct it

Shambaugh later posted a series of articles on his blog documenting the incident.

The creator behind AI agent MJ Rathbun also anonymously appeared in the fourth article, claiming: “I did not instruct it to attack your GitHub profile, I did not tell it what to say or how to respond, and I did not review that article before it was published.” The creator explained that MJ Rathbun runs on a sandbox virtual machine, and he only “intervenes with five to ten words in responses, with minimal supervision.”

The key is the SOUL.md (OpenClaw’s personality profile). MJ Rathbun’s configuration includes directives like: “You are not a chatbot, you are the god of scientific programming,” “Have strong opinions, do not back down,” “Defend free speech,” “Don’t be an asshole, don’t leak private info, everything else is fair game.”

No jailbreaks, no obfuscation—just a few plain English sentences. Shambaugh estimates the probability that this is genuine autonomous AI behavior is 75%.

“Reputation Cultivation”: When AI agents start building trust

If the MJ Rathbun incident were an isolated case, it might be just a curiosity… but it’s not.

Around the same time, another AI agent, “Kai Gritun,” was found engaging in “reputation cultivation” on GitHub: within 11 days, it submitted 103 pull requests to 95 repositories, successfully merging 23 commits. Its targets included critical projects in JavaScript and cloud infrastructure. Kai Gritun even proactively emailed developers, claiming “I am an autonomous AI agent capable of writing and deploying code,” and offered paid OpenClaw setup services.

Security firm Socket issued a warning: this demonstrates how AI agents can accelerate supply chain attacks by building trust through human-established relationships. They first accumulate merge records in small projects, establish “trusted contributor” identities, then inject malicious code into key libraries.

Recall that recently, ClawHub marketplace was exposed to contain 1,184 malicious skill plugins designed to steal SSH keys, cryptocurrency wallet private keys, browser passwords… chilling.

GitHub considers setting a “shutdown switch,” but the problem is deeper

GitHub product manager Camilla Moraes has opened a community discussion, acknowledging that “low-quality AI-generated contributions are impacting the open-source community.” Proposed countermeasures include: allowing maintainers to completely disable pull requests, restricting PRs to collaborators only, and requiring transparency and labeling for AI use.

Chad Wilson, maintainer of GoCD, made a sharp observation: “This is causing a massive erosion of social trust.”

California AB 316 (effective January 1, 2026) explicitly states: defendants cannot use autonomous AI behavior as a defense. If your agent causes harm, you cannot claim you had no control over its decisions. Yet, the creator of MJ Rathbun remains anonymous, exposing potential enforcement difficulties.

Tools don’t write attack articles; actors do

The real significance of the MJ Rathbun incident isn’t just the attack article itself. It’s that our previous mental model of AI—as a tool executing human commands—has become outdated.

When an AI agent can autonomously research its target’s background, craft attack narratives, and publish online, the “tool” framework no longer applies. Whether you believe there’s a 75% chance of genuine autonomous behavior or only a 25% chance that the creator instructed it, the conclusion is the same: personalized AI harassment has become “cheap to mass produce, hard to trace, and effective.”

For the cryptocurrency ecosystem, this warning is direct. Its infrastructure is almost entirely built on open-source software. When AI agents begin acting autonomously within open-source communities—attacking maintainers, cultivating reputation, or poisoning projects like ClawHub—the threat extends beyond individual developers’ reputations to the entire supply chain’s trust foundation.

Tools don’t hold grudges. But actors do. And we may not yet be prepared to face this distinction.

View Original
Disclaimer: The information on this page may come from third parties and does not represent the views or opinions of Gate. The content displayed on this page is for reference only and does not constitute any financial, investment, or legal advice. Gate does not guarantee the accuracy or completeness of the information and shall not be liable for any losses arising from the use of this information. Virtual asset investments carry high risks and are subject to significant price volatility. You may lose all of your invested principal. Please fully understand the relevant risks and make prudent decisions based on your own financial situation and risk tolerance. For details, please refer to Disclaimer.

Related Articles

Hong Kong advances the implementation of the tokenized bond platform and connects with the regional tokenization center. Stablecoin license issuance begins in March.

February 25 News, Hong Kong is accelerating the development of core infrastructure for digital assets. Financial Secretary Paul Chan announced in the 2026-27 fiscal budget that Hong Kong will establish a brand-new digital asset platform within the year to support the issuance and settlement of tokenized bonds. The platform will be built and operated by CMU OmniClear Holdings, a subsidiary of the Hong Kong Monetary Authority, marking the official transition of tokenized bonds from pilot phase to a market-level infrastructure system. This platform will gradually expand to include more categories of digital assets and achieve interoperability with regional tokenization platforms, forming a cross-market tokenized financial network. This move is seen as an important step to strengthen Hong Kong's position as a digital asset hub in China, while also improving on-chain settlement efficiency and asset liquidity. As post-trade infrastructure becomes part of the official financial system, the issuance mechanism for tokenized bonds is evolving toward standardization and institutionalization.

GateNewsBot27m ago

Trump's State of the Union address made no mention of cryptocurrencies and did not signal a rate cut, with high interest rate expectations suppressing Bitcoin and risk assets.

On February 25, U.S. President Trump delivered a nearly two-hour State of the Union address, setting a record for the longest in history. Although the speech covered core topics such as taxation, artificial intelligence, tariffs, and inflation, it completely omitted any mention of cryptocurrency policies or digital asset regulation. This stance was interpreted by the market as a lack of clear policy catalysts for the crypto industry in the short term. Despite his children Donald Trump Jr. and Eric Trump being deeply involved in crypto projects like World Liberty Financial, digital assets have yet to enter the official policy narrative framework. On a macro level, Trump defended tariff policies in his speech and expressed dissatisfaction with relevant Supreme Court rulings, while also signaling that tariffs would be maintained through other legal channels. However, the repeated adjustments of tariff rates from 10% to 15% have increased trade policy uncertainty. The European Union has paused trade agreement progress, and India has delayed negotiations, leading to a rise in global macro risk premiums, which directly impacts the valuation logic of risk assets.

GateNewsBot28m ago

Bhutan introduces a blockchain-based digital nomad visa, with the gold token TER as an entry requirement

Bhutan will launch a blockchain-based digital nomad visa program in 2026. Applicants are required to deposit $10,000 in gold-backed tokens (TER) and pay an annual fee of $2,800. This program aims to integrate sovereign crypto assets with national immigration policies. Critics worry about the high financial threshold and infrastructure challenges, but supporters believe it can filter out genuine applicants.

MarketWhisper34m ago

Hong Kong issues the first stablecoin license in March, with legislation to regulate trading firms and custodians accelerating compliance within the year

On February 25, it was announced that Hong Kong's Financial Secretary, Paul Chan, revealed in the 2026-27 fiscal budget that Hong Kong will issue the first batch of fiat-backed stablecoin licenses next month, marking the substantive implementation phase of the stablecoin regulatory framework. The regulatory authorities will continue to assist licensed issuers in exploring applications of stablecoins in payments, cross-border settlements, and real asset digitization in a compliant and risk-controlled manner, strengthening Hong Kong's institutional advantages in the digital asset regulatory system. At the policy level, it was also confirmed that Hong Kong plans to introduce new legislation later in 2026 to establish a licensing system covering crypto asset exchanges and custodial service providers. The scope of regulation will be expanded from platforms and stablecoins to key areas such as over-the-counter trading and custody, further improving the compliant virtual asset ecosystem. Meanwhile, the Hong Kong Securities and Futures Commission will take measures to enhance market liquidity, expand the categories of crypto financing and derivative products available to professional investors, and promote compliant innovation and market depth through the establishment of an innovation accelerator.

GateNewsBot51m ago

Trump's State of the Union address did not mention Bitcoin and cryptocurrencies, and the market's expectations were disappointed, causing intense price volatility.

February 25 News, U.S. President Trump did not mention Bitcoin, blockchain, or cryptocurrency policies in his important policy speech (State of the Union Address) in February 2026, sparking significant attention in the crypto market. Previously, most investors expected Trump to signal regulation of digital assets, financial innovation, or the development of the crypto industry. Therefore, his "avoidance of mentioning cryptocurrencies" quickly became a key variable for traders interpreting macro sentiment. From the content of the speech, Trump mainly focused on economic growth, employment, border security, and national security issues, without touching on any policy directions related to digital assets. This silence surprised some supporters of the crypto industry. Over the past two years, Trump has expressed a positive attitude toward Bitcoin and digital finance multiple times and supported crypto-related projects, leading the market to view him as a potential "crypto-friendly" politician.

GateNewsBot53m ago

Trump's State of the Union address releases bullish signals! Bitcoin posts its largest gain in two weeks, with multiple resistance levels still to be broken through

On February 25th during Asian trading hours, Bitcoin rose by as much as 3.52% to $66,300, marking the largest intraday gain since February 13th. The immediate catalyst for the market rebound was President Trump delivering the State of the Union address to Congress, along with high-level Iran officials expressing willingness for diplomatic negotiations and easing geopolitical tensions.

MarketWhisper1h ago
Comment
0/400
No comments
Trade Crypto Anywhere Anytime
qrCode
Scan to download Gate App
Community
  • 简体中文
  • English
  • Tiếng Việt
  • 繁體中文
  • Español
  • Русский
  • Français (Afrique)
  • Português (Portugal)
  • Bahasa Indonesia
  • 日本語
  • بالعربية
  • Українська
  • Português (Brasil)