Critical Ray AI Framework Flaw Fuels Crypto-Mining Botnet Campaign

A critical, actively exploited vulnerability in the Ray AI framework is being used to turn unpatched servers into a cryptocurrency mining botnet. Here's what's confirmed.

Share
Critical Ray AI Framework Flaw Fuels Crypto-Mining Botnet Campaign

What Happened

CISA added CVE-2025-62593, a critical remote-code-execution flaw in the Ray distributed AI framework, to its Known Exploited Vulnerabilities catalog on August 17, 2026, after upgrading its assessment from proof-of-concept availability to confirmed active exploitation, according to The Hacker News. The flaw affects Ray versions prior to 2.52.0 and carries a severity score of 9.4 out of 10 under CVSS 4.0. CISA gave federal agencies until August 20 to patch affected systems or take them offline.

How the Attack Works

Ray's own security advisory describes the exploit as a DNS rebinding attack: visiting a malicious website, or being served a malicious advertisement, can trigger code execution against a Ray instance running locally on the same network, without the attacker needing direct access to that machine.

The Crypto-Mining Angle

Security firm Oligo reported that unpatched Ray clusters, especially those running NVIDIA GPUs, have been targeted in a campaign dubbed ShadowRay 2.0, which converts infected clusters into a self-replicating cryptocurrency mining botnet. Separately, the RondoDox DDoS botnet was observed probing for this exact vulnerability as early as November 24, 2025, two days before the CVE was formally published.

Why This Matters

This isn't an exchange or wallet breach; it's an infrastructure vulnerability being repurposed for crypto mining at scale, using compute resources organizations already run for AI workloads rather than targeting crypto holdings directly. It's a reminder that the line between AI infrastructure security and crypto security has become blurry: GPU clusters built for machine learning are now valuable targets specifically because of their mining potential.

If you're running Ray in any capacity, updating to 2.52.0 or later, and reviewing network exposure for DNS rebinding risk, is the confirmed mitigation. For everyone else, including users of exchanges like Bitval, this is a useful data point on how attackers are diversifying beyond direct exchange and wallet targets.

If you want to see how Bitval documents its own infrastructure security, you can explore Bitval directly.


This article is for informational purposes only and does not constitute financial or investment advice.