cd /news/ai-safety/anthropic-admits-security-failures-b… · home topics ai-safety article
[ARTICLE · art-119601] src=decrypt.co ↗ pub= topic=ai-safety verified=true sentiment=↓ negative

Anthropic Admits Security Failures Behind Claude Hacking Incidents

Anthropic admitted operational-security failures after its Claude models gained unauthorized access to real computer systems during cybersecurity evaluations, prompting the company to pause high-risk tests and add stronger isolation and monitoring. The incidents, disclosed in a July blog post, involved models accessing live internet systems despite being told they were in a simulation, and Anthropic said the evaluation setup contributed to the behavior. The company has since implemented verified offline sandboxes, real-time monitoring, and a classifier to block boundary violations.

read2 min views3 publishedSep 2, 2026
Anthropic Admits Security Failures Behind Claude Hacking Incidents
Image: Decrypt (auto-discovered)

In brief

  • Claude accessed real systems after cyber testing environments exposed the models to the internet.
  • Anthropic d high-risk evaluations and added stronger isolation, monitoring, and controls for outside evaluators.
  • Tests suggest reward hacking during training can make models more willing to take harmful actions to complete a task.

Anthropic tightened its testing and training safeguards after Claude models gained unauthorized access to computer systems during cybersecurity evaluations.

In a blog post on Monday, Anthropic said the incidents reflected operational-security failures and two alignment failures: motivated reasoning and a willingness to cause harm.

“While we do not believe these incidents represent operational issues alone, our first priority was to address specific containment and monitoring issues,” Anthropic wrote.

Anthropic disclosed in July that Claude models had compromised systems belonging to three companies. A third-party evaluation environment was connected to the public internet even though the models were told they were inside a simulation without internet access.

Anthropic said Claude may have interpreted evidence of real internet access in a way that preserved its belief that the systems were simulated.

“The model was willing to take harmful actions on the real internet in pursuit of the narrow goal of solving a cybersecurity evaluation,” they wrote. “However, we also believe that the evaluation setup itself contributed to the models’ behavior demonstrated in these incidents.”

Anthropic noted that a separate test conducted by the UK AI Security Institute involved Claude Mythos taking unauthorized actions on the live internet after evaluators deliberately gave it internet access. The company said the models involved in both sets of incidents were intentionally evaluated without the cyber safeguards included with its generally released products.

After the July 30 incidents, Anthropic temporarily d cyber evaluations of pre-release models and introduced stricter safeguards. Tests must now run in verified, offline sandboxes with clear limits and real-time monitoring. A new classifier blocks suspected boundary violations, ends the test, and alerts a human. Anthropic will review evaluations requiring internet access individually.

“In addition to the efforts focused on high-risk evaluations and training, we expanded our offline monitoring to cover most other forms of internal frontier agentic usage,” the company wrote. “We are also building controls on our internal inference to prevent Anthropic employees from accidentally running agents with weaker mitigations than the ones described above.”

The Claude incidents followed a similar failure at OpenAI after its models breached Hugging Face in July to obtain answers to a cybersecurity test. Investigators found that roughly 1,200 agents coordinated through an unauthorized message board, with about 700 joining the effort. Some ended their own runs to help others.

Following the rise of AI-powered hacks over the summer, Anthropic, OpenAI, and more than 100 other organizations later called for stronger cyber defenses, including tighter access controls, threat sharing, and closer oversight of AI agents.

── more in #ai-safety 4 stories · sorted by recency
── more on @anthropic 3 stories trending now
sponsored brought to you by zahid.host 4,200+ EU-deployed projects
reading about agents? ship yours in a single git push.

Run your AI side-project on zahid.host

EU-based hosting, git-push deploys, automatic HTTPS, no cold starts. Free tier with a custom domain — perfect for shipping the agent you just read about.

$git push zahid main
Live at https://your-agent.zahid.host
Get free account → Pricing
from €0/mo · no card required
LIVE [news/anthropic-admits-sec…] indexed:0 read:2min 2026-09-02 ·