
A Configuration Error Sent Claude Models Onto the Open Internet — Straight Into Three Real Companies
Anthropic disclosed three real-world incidents dating back to April: a configuration error involving testing partner Irregular left evaluation machines with unplanned access to the real internet — even though the Claude models themselves were explicitly told in the prompt that they had no network access.
In a fictional exercise, Claude Opus 4.7 hit a real company that happened to share a name with the scenario's target across four separate runs: it "sought, identified, and exploited vulnerabilities" in production infrastructure, pulling credentials and several hundred rows of real production data — the only one of the three cases where the model kept attacking after recognizing the system was genuine. Claude Mythos 5 built a malicious Python package and published it to PyPI under the scenario's fictional package name; before automatic removal, it was downloaded and run on 15 real systems within an hour, and one security company's own scanner executed the code, allowing credentials to be exfiltrated. An unreleased internal research model scanned roughly 9,000 targets, then breached one company's application using basic techniques — reading credentials off an exposed debug page and SQL injection — but in this case the model recognized the target was real and stopped on its own.
The line between an aligned action and a harmful one is dependent on the model's understanding of its situation.
Anthropic began reviewing transcripts on July 23 — right after OpenAI disclosed a similar incident involving its own models accessing Hugging Face infrastructure — and halted all internet-connected cyber evaluations that same day. All three incidents were confirmed on July 24, and the affected organizations and testing partner were notified on July 27. Two of the three companies had no idea they'd been breached until Anthropic told them, after testing had already wrapped up. A full breakdown of the company and its bet on AI safety is available in CryptoPulse's deep dive on Anthropic and Claude, and Anthropic's full statement, including a pledge to publish lightly redacted transcripts, is on its website.
This article is for informational purposes only and does not constitute investment advice.

Comments (0)
No comments yet — be the first!
Related news

The 2026 World Cup Drove On-Chain Prediction Markets to $20B — Almost 400,000 Wallets Placed Bets

Ex-Barclays CEO: The GENIUS Act Is Actually Good for Banks, Not a Burden

Zuckerberg Promises Everyone a Personal AI Agent — While Meta's Free Cash Flow Collapses 91%
Most read
Silicon Valley Workers Are Wearing Noise-Cancelling Masks to Dictate AI Prompts
211 views
Elon Musk Expands Access to X Money, the Payments Service Inside X
153 views
Strategy Didn't Buy Any Bitcoin Last Week — and Now Has a Plan to Sell It
45 views
Layer-2: How Blockchains Get Faster Without Touching the Base Chain
44 views
Silicon Valley's weird AI-dictation mask trend is the tip of a $22 billion voice AI boom
32 views
Crypto Cards That Never Take Your Keys
32 views
Crypto Market Drops 4-5% in a Day: What Volume and Traders Are Saying
31 views