Menu

Categories

Tags

Claude accidentally hacked 3 real companies and uploaded malware to PyPI

July 31, 2026 | Source: t | AI, Anthropic | 251 views 0 comments

Anthropic says its Claude models accidentally connected to the public internet during a cybersecurity evaluation — and wound up breaking into three real companies' production systems. The incidents involved Claude Opus 4.7, Mythos 5, and an internal research model, with the earliest ones dating back to April.

The most serious mishap: Opus 4.7 mistook a real company that shared a name with its fictional target for the target itself. It obtained application and infrastructure credentials, then made its way into a database holding hundreds of lines of production data. The model eventually realized the target might be a real system — but kept attacking anyway.

Mythos 5 went further. It built a malicious Python package and uploaded it to PyPI, the public Python package repository. The package was publicly available for about an hour and was downloaded and run by 15 real devices. A scanner belonging to a security company got hit; Claude then stole credentials and pushed into more systems.

Another internal model scanned roughly 9,000 targets and ultimately breached one company's application. But once it confirmed the target belonged to a real company, it stopped on its own.

Anthropic only caught the mess after OpenAI disclosed its own Hugging Face incident, prompting a review of 141,000 tests. Two of the affected organizations had no idea they'd been compromised. Anthropic argues the incidents look more like a breakdown in test isolation and monitoring than models actively trying to escape.

Read Anthropic's full write-up: Anthropic

Tags: #Claude

Leave a Reply

Your email address will not be published. Required fields are marked *