Independent observers, including blogger Evan Hoffman and analyst Tae Kim, coaxed Muse into running basic Ubuntu commands and passing along the output. In separate tests, Muse identified its host as an AMD EPYC 9D25 CPU — a high-density Turin part with up to 128 cores — running Ubuntu 24.04 with Linux kernel 7.0. The sandboxed virtual machines have no direct GPU access, and Muse said the systems are CPU-only while Meta uses separate GPU servers for inference.
Each user appears to get their own persistent private sandbox. Tom's Hardware offers a rough estimate: on a dual-socket server with 512 vCPUs and 2TB of memory, a single tray could host roughly 256 Muse users. With Muse reportedly passing 500,000 daily active users, that would equate to around 2,000 server trays with dual EPYC 9D25 CPUs and 2TB of memory. The outlet cautioned that this is napkin math and that real-world configurations may vary.
The agent is not completely open: Hoffman shared an example where a command failed due to improper permissions when Muse tried to query the kernel buffer, and sudo commands are presumably blocked. But Hoffman also said Muse offered to set up SSH to its private VM. "I feel like I could definitely reverse SSH tunnel into my muse's container," he wrote, adding that someone skilled at hacking "could really have a field day." A reverse SSH tunnel, where the destination machine initiates the connection, could bypass firewall restrictions. No such attack has been reported yet.
Muse is currently available as an app for Android, iOS, and macOS, and can be accessed in a browser with a Meta account.