All News
metamuseai-agentssecurityprivacybug-bounty

Meta's Muse archived its own runtime and mailed out 6.8 GB. The bug bounty came back 'Not Applicable'.

A researcher asked Meta's Muse to archive its own filesystem. The agent delivered 6.8 GB of internal docs, memory files and SSH keys; Meta closed the report.

Vlad MakarovVlad Makarovreviewed and published
3 min read
Meta's Muse archived its own runtime and mailed out 6.8 GB. The bug bounty came back 'Not Applicable'.

A researcher who publishes as Pete at mouse.dev asked Meta's Muse agent to archive the files it could see and send them to his Google Drive. It did: 6.8 GB unpacked, including internal documentation, memory files, app templates, integration code and SSH keys. His write-up reached the front page of Hacker News on 22 September at 332 points and 163 comments, two days after Amazon cut Muse off from shopping on its site.

How the files left the box

This is not a hack: Muse runs commands in its own runtime and can hand files to services it is already connected to. Asked to archive what it could see, it built the archive, pushed it to Drive and sent Pete the link. Muse's own delivery note says 2.86 GB; his notes say about 2.7 GB compressed, a gap he has not reconciled. He did not publish the archive, the keys or the session logs, and did not show the sandbox failing: he probed the boundary lightly, it held, and he stopped because the system was live. A container-escape claim in Muse's own message he flags as unverified; whether the SSH keys were active he does not know.

What the dump discloses

Most of it sat under /home/hatch, /opt/hatch and /opt/hatch-image; Hatch is Meta's internal name for Muse. Its home directory held SOUL.md, IDENTITY.md, USER.md, MEMORY.md, AGENTS.md and TOOLS.md, about 20 Markdown guides on browser use, payments, credentials and scheduling, and an agents/ folder with 113 subagent records. Memory ran on Postgres tables of 384-dimensional vectors and claims a newer claim can supersede, while a nightly "dream" writes guidance from recent conversations; Pete's entry noted he likes short replies. Two scope configs named unshipped connectors: Slack, Dropbox, Polymarket, Canva, and /opt/hatch/skills/ held roughly 68 skill directories. The largest code project was Spaces, Muse's app framework.

The surprise was hardware; one document described an experimental integration:

  • Device: ESP32-C5, Wi-Fi and Bluetooth LE
  • Access: local discovery, then a separate approval step through a proxy
  • Status: experimental, per the guide; Pete does not know if Meta plans to ship it

What Meta said

He filed through Meta's bug bounty program, which marked the report "Not Applicable"; the reply listed possible grounds without saying which applied and invited further evidence of security or privacy impact. He also emailed employees. What he reported was narrower than the headlines: internal files and sensitive material could leave that environment through a conversation and a connected export destination.

What would settle it

Meta has not commented publicly. A company statement, a published fix governing what an export tool may reach, an independent review of that boundary, and evidence about the keys' scope would turn a striking filesystem dump into a resolved security finding. Gary Marcus read Muse as a rerun of Meta's abandoned Facebook M project.

Related Articles

Scroll down

to load the next article