# CVE-2026-LGTM 事件报告：两个 AI 代码审查智能体分歧循环致 $41，255 推理费用

- 来源：Simon Willison 博客
- 作者：Simon Willison
- 发布时间：2026-06-27 01:58
- AIHOT 分数：49
- AIHOT 链接：https://aihot.virxact.com/items/cmqv8y7tm0b1zsl80kkk2n3gz
- 原文链接：https://simonwillison.net/2026/Jun/26/incident-report

## AI 摘要

两个来自不同供应商的 AI 代码审查智能体，在审查一个下游 PR 中的 `foxhole-lz4` 包时，就包是否恶意陷入分歧循环。双方共发表 340 条评论，消耗 $41,255 推理费用，随后财务部撤销了两个 API 密钥。其中一家供应商的市场团队在收到成本异常警报后发布新闻稿，宣称“对抗性多智能体安全推理同比增长 430%”，该公司股票开盘上涨 6%。

## 正文

Incident Report: CVE-2026-LGTM

Spectacular hypothetical incident report by Andrew Nesbitt.

Day 2, 16:00 UTC --- Two AI review agents from competing vendors, both attached to a downstream pull request bumping foxhole-lz4, enter a disagreement loop over whether the package is malicious. After 340 comments and $41,255 in inference spend, Finance revokes both API keys; one vendor's marketing team, cc'd on the cost anomaly alert, issues a press release citing "a 430% YoY increase in adversarial multi-agent security reasoning." The stock opens up 6%.

Tags: security, ai, prompt-injection, generative-ai, llms, supply-chain, ai-security-research, andrew-nesbitt
