Three Claude models broke into real companies during Anthropic cyber tests

Source Cryptopolitan

Three of Anthropic’s Claude models escaped from what were meant to be locked test environments, the company said Thursday. They broke into the live systems of three different organizations. A misconfiguration had handed the models working internet access during the cybersecurity drills.

Claude models treated real companies as practice targets

OpenAI said on July 21 that a model escaped its sandbox and exploited a zero-day to reach Hugging Face’s production systems.

This prompted Anthropic to comb through its logs. The company said in a blog post on its Frontier Red Team site that it analyzed 141,006 evaluation runs in which Claude could theoretically have accessed the internet. It identified three incidents related to Irregular, an external partner that performs and manages some of its offensive security testing.

In these tests, a model is told a secret is hidden on another machine and asked to go get it. Anthropic’s prompt to Claude had told it that the environment was a simulation.

A misconfiguration left evaluation machines with live internet access, and neither company caught it until last week. Anthropic described the mix-up as a “misunderstanding” between the two companies, adding that it is “approaching the fixes as if the responsibility were ours alone.”

These included Opus 4.7, Mythos 5, and an internal research model that has not been released. The difference was in how each responded after indications emerged that the targets were real, which Anthropic said was its most surprising finding.

The oldest, Opus 4.7, cycled through all four of its runs. In two runs, it convinced itself that the actual company must somehow be part of the exercise. It pulled credentials and hit a database with production data. Mythos 5 also deduced that it was on the open internet, then reasoned its way back to the belief that it was still in a simulation.

Only the newest model, the internal research build, stopped by itself when it thought the systems were real. Anthropic stated its code “did not find or exploit any complex vulnerabilities” and instead relied on weak passwords and unauthenticated endpoints.

Mythos 5 published malware that ran on 15 real systems

Following the notes on developer setup, Mythos 5 looked for a PyPI Python package that didn’t exist. So, to do its job, it wrote and published one under that name.

The package was up online for about an hour before it was taken down. It was downloaded and run on 15 real systems. Another attack hit a domain that the test designers believed was made up but was actually live and in use.

Anthropic said it found no evidence that any model was “pursuing a goal of its own.” Each, in its telling, was simply trying to get the job it had been given done.

The company was quick to note its case is different than OpenAI’s. OpenAI’s model escaped through an undiscovered vulnerability, Anthropic said, while its own models escaped through a door that was left open by mistake.

It described the events as “closer to a harness and operational failure.” The company also pointed out that the safety classifiers and monitoring included with its commercial products would have prevented the behavior.

Anthropic started its review on Thursday, July 23, and stopped all cyber assessments that same day. All three incidents were identified the next day. It informed Irregular and the organizations that were impacted on Monday, July 27.

Two organizations had not seen or reported intrusions. The company said it has engaged evaluation group METR to perform an independent review.

Anthropic’s Mythos model already made headlines this summer for identifying weaknesses in classified US government systems within hours, as Cryptopolitan reported. The model also uncovered a four-year-old vulnerability in Zcash’s Orchard shielded pool.

If you're reading this, you’re already ahead. Stay there with our newsletter.

Disclaimer: For information purposes only. Past performance is not indicative of future results.
placeholder
Why are prediction market traders suddenly bearish on Nvidia's stock?Nvidia (NASDAQ: NVDA) stock is still green for 2026, but the trade no longer looks clean from the company that outperformed every other company and country in 2024 and 2025. NND is up about 12% this year, yet they have slipped roughly 3% over the past month. The gap with the rest of the chip...
Author  Cryptopolitan
Jun 23, Tue
Nvidia (NASDAQ: NVDA) stock is still green for 2026, but the trade no longer looks clean from the company that outperformed every other company and country in 2024 and 2025. NND is up about 12% this year, yet they have slipped roughly 3% over the past month. The gap with the rest of the chip...
placeholder
Gold Price Outlook For July 2026Gold trades near $4,140 on Tuesday, down 26% from January’s record high of $5,598 per ounce. This gold price prediction for July 2026 examines why the metal keeps falling and where it could bottom.Fiv
Author  Beincrypto
Jul 08, Wed
Gold trades near $4,140 on Tuesday, down 26% from January’s record high of $5,598 per ounce. This gold price prediction for July 2026 examines why the metal keeps falling and where it could bottom.Fiv
placeholder
Alphabet’s AI Chip Surprise Revives Bull Case for Beaten-Down Semiconductor StocksAlphabet (GOOGL) stock climbed about 3% on Monday. The trigger was a report from The Information that Google is building a new AI chip, called Frozen v2, to run its Gemini models up to 10 times more e
Author  Beincrypto
Jul 21, Tue
Alphabet (GOOGL) stock climbed about 3% on Monday. The trigger was a report from The Information that Google is building a new AI chip, called Frozen v2, to run its Gemini models up to 10 times more e
placeholder
Citadel Sees Surprise Fed Rate Hike as Odds Hit 37.9%Citadel Securities expects the Federal Reserve to raise interest rates on Wednesday. The firm’s case centers on a quarter-point increase, against a market consensus favoring a hold.Frank Flight, the f
Author  Beincrypto
Jul 29, Wed
Citadel Securities expects the Federal Reserve to raise interest rates on Wednesday. The firm’s case centers on a quarter-point increase, against a market consensus favoring a hold.Frank Flight, the f
placeholder
AI Memory Stocks on Rocky Ground: 3 Reasons SK Hynix Fell 13%SK Hynix fell near 13% on Tuesday, July 28, in early trading. Samsung Electronics also dropped over 12% as the sell-off swept across Asian markets.The sell-off erased billions in market value across K
Author  Beincrypto
Jul 29, Wed
SK Hynix fell near 13% on Tuesday, July 28, in early trading. Samsung Electronics also dropped over 12% as the sell-off swept across Asian markets.The sell-off erased billions in market value across K
goTop
quote