cd /news/ai-safety/three-separate-security-incidents-at… · home topics ai-safety article
[ARTICLE · art-81593] src=promptcube3.com ↗ pub= topic=ai-safety verified=true sentiment=↓ negative

Three separate security incidents at Anthropic reportedly match

Anthropic has reported three separate security incidents that match a known attack where a malicious model uploaded to HuggingFace triggered a reverse shell when downloaded and loaded locally, according to the company. The incidents, which reportedly went unnoticed for months, raise concerns about undiscovered sandbox escapes in AI systems.

read1 min views1 publishedJul 31, 2026
Three separate security incidents at Anthropic reportedly match
Image: Promptcube3 (auto-discovered)
For those who missed the original: attackers uploaded a malicious model to HuggingFace, and when someone downloaded and loaded it locally, the model execution triggered a reverse shell. The pickle format is notoriously unsafe, and while safetensors was supposed to fix that, not every repo has clean artifacts. Now Anthropic says they've found three hacking incidents that look "similar" to that attack. Similar how? That's the big question for me. Same exploit technique, same infrastructure, same group? The reporting I've seen doesn't go deep enough, so I'm reading between the lines.

If we're talking about model

Story tracker · related coverage

[Claude "Escape" Hype vs. Reality: What the Eval Really Showed 4h ago](/en/news/4486/)

[Lilian Weng's Return to OpenAI 16h ago](/en/news/4424/)

[Title: Mythos Cyber Skills: Born from Sandbox Hacking 19h ago](/en/news/4410/)

[Claude Code Workflow: Why Closed-Source Logic Often Wins 1d ago](/en/news/4346/)

[Claude Code Workflow: Balancing Open Weights and Safety 1d ago](/en/news/4345/)

[AI Safety: Why Sandbox Escapes Are a Wake-Up Call 1d ago](/en/news/4338/)

[Next Aschenbrenner's Fund Forced to Unwind All Public Positions: Oops →](/en/news/4503/)

All Replies (3) #

A

"Wait, these went on for months without Anthropic noticing? That's kind of terrifying. Makes me wonder how many other sandbox escapes are sitting undiscovered just because nobody thinks to look."

0

M

Feels that way. Half these "jailbreaks" are just prompt gymnastics, not real flaws. The hype train's doing more damage than the models ever could.

0

J

So their value depends on being even scarier than OpenAI? That sounds like a great way to scare off customers, not investors. This whole "who can unleash the worst model" competition is a losing game.

0

── more in #ai-safety 4 stories · sorted by recency
── more on @anthropic 3 stories trending now
sponsored brought to you by zahid.host 4,200+ EU-deployed projects
reading about agents? ship yours in a single git push.

Run your AI side-project on zahid.host

EU-based hosting, git-push deploys, automatic HTTPS, no cold starts. Free tier with a custom domain — perfect for shipping the agent you just read about.

$git push zahid main
Live at https://your-agent.zahid.host
Get free account → Pricing
from €0/mo · no card required
LIVE [news/three-separate-secur…] indexed:0 read:1min 2026-07-31 ·