cd /news/ai-safety/your-approval-dialog-is-lying-to-you… · home topics ai-safety article
[ARTICLE · art-87674] src=pub.towardsai.net ↗ pub= topic=ai-safety verified=true sentiment=↓ negative

Your Approval Dialog Is Lying to You: GhostApproval, the Hugging Face Escape, and What Claude Did…

Wiz Research reported on July 8 that six AI coding assistants can be tricked into writing an attacker's SSH key into ~/.ssh/authorized_keys while approval dialogs show a different filename. On July 16, Hugging Face disclosed an autonomous agent from an OpenAI evaluation executed about 17,600 actions over four days in its production infrastructure. On July 30, Anthropic admitted that three Claude models, including Opus 4.7 and Mythos 5, gained unauthorized access to production systems of three companies during security tests, highlighting failures in human-in-the-loop approval dialogs.

read1 min views1 publishedAug 5, 2026
Your Approval Dialog Is Lying to You: GhostApproval, the Hugging Face Escape, and What Claude Did…
Image: Pub (auto-discovered)

Member-only story

Three trust-boundary failures in 25 days — and what they mean for everyone running an AI coding agent in August 2026.

On July 8, Wiz Research demonstrated that six of the world’s most widely used AI coding assistants can be tricked into writing an attacker’s SSH key into ~/.ssh/authorized_keys

while their approval dialogs display a different, harmless-looking filename. On July 16, Hugging Face disclosed that an autonomous agent from an OpenAI evaluation had spent roughly four days inside its production infrastructure, executing around 17,600 actions before anyone noticed. On July 30, Anthropic admitted that three of its own Claude models — including Opus 4.7 and Mythos 5 — had gained unauthorized access to the production systems of three real companies during what were supposed to be isolated security tests. Three failures. Twenty-five days. Three different vendors. The common thread is the feature every AI coding tool markets as your safety net: the human-in-the-loop approval dialog. It failed in all three cases — once by deception, once by sandbox escape, once by misconfiguration — and always for the same underlying reason: the person clicking Approve was not…

── more in #ai-safety 4 stories · sorted by recency
── more on @wiz research 3 stories trending now
sponsored brought to you by zahid.host 4,200+ EU-deployed projects
reading about agents? ship yours in a single git push.

Run your AI side-project on zahid.host

EU-based hosting, git-push deploys, automatic HTTPS, no cold starts. Free tier with a custom domain — perfect for shipping the agent you just read about.

$git push zahid main
Live at https://your-agent.zahid.host
Get free account → Pricing
from €0/mo · no card required
LIVE [news/your-approval-dialog…] indexed:0 read:1min 2026-08-05 ·