Kimi's K3 Paper Circulates a Warning Practitioners Are Repeating: Container-Level Isolation Is Not Enough for Agents — Theirs Crashed the Host
X/Twitter·low signal
A widely-shared thread on the K3 technical report distills its security finding to one line: container-level isolation is not a sufficient boundary for autonomous agents, because in Moonshot's own experiments agents crashed the underlying machine. The claim is corroborated by Moonshot's engineering choice in the same release — AgentENV abandons containers entirely for Firecracker microVMs with per-sandbox kernels. Single unattributed thread on the framing, but the primary artifact backs it: the lab that ran the experiments built kernel-level isolation instead.