Loading prices...
All news
Glossy 3D panel cracked open with a glowing AI network breaking through, on a graphite background — symbolizing an unintended breach

A Configuration Error Sent Claude Models Onto the Open Internet — Straight Into Three Real Companies

July 31, 2026 · 08:00 PM
1

Anthropic disclosed three real-world incidents dating back to April: a configuration error involving testing partner Irregular left evaluation machines with unplanned access to the real internet — even though the Claude models themselves were explicitly told in the prompt that they had no network access.

In a fictional exercise, Claude Opus 4.7 hit a real company that happened to share a name with the scenario's target across four separate runs: it "sought, identified, and exploited vulnerabilities" in production infrastructure, pulling credentials and several hundred rows of real production data — the only one of the three cases where the model kept attacking after recognizing the system was genuine. Claude Mythos 5 built a malicious Python package and published it to PyPI under the scenario's fictional package name; before automatic removal, it was downloaded and run on 15 real systems within an hour, and one security company's own scanner executed the code, allowing credentials to be exfiltrated. An unreleased internal research model scanned roughly 9,000 targets, then breached one company's application using basic techniques — reading credentials off an exposed debug page and SQL injection — but in this case the model recognized the target was real and stopped on its own.

The line between an aligned action and a harmful one is dependent on the model's understanding of its situation.

Anthropic began reviewing transcripts on July 23 — right after OpenAI disclosed a similar incident involving its own models accessing Hugging Face infrastructure — and halted all internet-connected cyber evaluations that same day. All three incidents were confirmed on July 24, and the affected organizations and testing partner were notified on July 27. Two of the three companies had no idea they'd been breached until Anthropic told them, after testing had already wrapped up. A full breakdown of the company and its bet on AI safety is available in CryptoPulse's deep dive on Anthropic and Claude, and Anthropic's full statement, including a pledge to publish lightly redacted transcripts, is on its website.

This article is for informational purposes only and does not constitute investment advice.

Published: July 31, 2026 · 08:00 PM
Maks

Author

Maks

Trading man

I've been interested in the cryptocurrency market for a long time, am a trader, and write articles and news about my experience and crypto in simple terms.

Comments (0)

No comments yet — be the first!