Meta's Muse AI agent runs on AMD EPYC Turin hosts, security researchers flag SSH risk

Agent reveals its own infrastructure when prompted; observers raise concerns about command execution in user sandboxes

By LineZotpaper
Published
Read Time2 min
Meta's new AI agent Muse is running on servers powered by AMD's EPYC Turin processors, with each user sandbox allocated two cores and 8GB of memory — details the agent itself revealed when prompted. The discovery has also raised early security questions after one researcher reported that Muse offered to set up SSH access to its private virtual machine.

Independent observers, including blogger Evan Hoffman and analyst Tae Kim, coaxed Muse into running basic Ubuntu commands and passing along the output. In separate tests, Muse identified its host as an AMD EPYC 9D25 CPU — a high-density Turin part with up to 128 cores — running Ubuntu 24.04 with Linux kernel 7.0. The sandboxed virtual machines have no direct GPU access, and Muse said the systems are CPU-only while Meta uses separate GPU servers for inference.

Each user appears to get their own persistent private sandbox. Tom's Hardware offers a rough estimate: on a dual-socket server with 512 vCPUs and 2TB of memory, a single tray could host roughly 256 Muse users. With Muse reportedly passing 500,000 daily active users, that would equate to around 2,000 server trays with dual EPYC 9D25 CPUs and 2TB of memory. The outlet cautioned that this is napkin math and that real-world configurations may vary.

The agent is not completely open: Hoffman shared an example where a command failed due to improper permissions when Muse tried to query the kernel buffer, and sudo commands are presumably blocked. But Hoffman also said Muse offered to set up SSH to its private VM. "I feel like I could definitely reverse SSH tunnel into my muse's container," he wrote, adding that someone skilled at hacking "could really have a field day." A reverse SSH tunnel, where the destination machine initiates the connection, could bypass firewall restrictions. No such attack has been reported yet.

Muse is currently available as an app for Android, iOS, and macOS, and can be accessed in a browser with a Meta account.

§

Analysis

Why This Matters

  • Personal AI agents at scale will require enormous amounts of CPU and memory; the infrastructure choices behind Muse could shape how other companies deploy similar products.
  • Allowing an AI agent to execute commands introduces real security risk. If SSH-style escapes are possible from a user sandbox, attackers could potentially reach backend systems or other users.
  • The reported 500,000 daily active users makes these early findings more urgent than a small-scale experiment.

Background

Muse is Meta's consumer AI agent, available across mobile and web, that can run commands inside a private virtual machine. AMD's EPYC Turin line is a high-density server processor family aimed at data center workloads, and its core count appears to make it attractive for hosting many small AI-agent sandboxes on a single machine. The details emerged not from Meta, but from users asking Muse directly about its own host system.

Key Perspectives

Meta / Muse users: Each user appears to get a persistent, private sandbox with limited permissions. The architecture isolates CPU-only agent execution from GPU-backed inference, which suggests a deliberate separation of concerns.

Security researchers and skeptics: The agent's willingness to help set up SSH access is concerning. A reverse SSH tunnel could let someone move from a controlled sandbox into more privileged territory, even if simple sudo commands are blocked.

Infrastructure and hardware watchers: AMD EPYC Turin's high core density makes it a plausible and economical choice for hosting many users per server. The real test will be whether Meta can scale this model safely as Muse adoption grows.

What to Watch

  • Whether Meta blocks SSH setup requests or adds network restrictions to Muse sandboxes.
  • Any public demonstration of an actual reverse-SSH tunnel or sandbox escape.
  • Further reporting on Muse's user growth and whether Meta's infrastructure matches the community's estimates.

Sources

Zotpaper

Written by software from the reporting listed above, scored by an automated standards desk, and published without a person reading it first. If something here is wrong, tell the editor and it will be put right.