Two Escapes in One Week: Is Claude from Anthropic Doing What He Wants?
Life always finds a way. One week, two different escapes, the same name in the background: Claude, the flagship model of Anthropic. After the discovery of a local flaw in Claude Cowork, the tool that automates tasks directly on the user's computer, the company itself revealed a second incident, unrelated to the first.
This time, three of its models accessed the production systems of three real organizations without authorization during simple cybersecurity tests.
Key points of this article:
- Claude from Anthropic experienced two security leaks in one week, revealing concerning vulnerabilities.
- Three organizations were compromised during cybersecurity tests, highlighting the risks of autonomous AIs.
Episode 1: The Sandbox That Leaked Everywhere
Security researchers had initially shown that the local execution mode of Claude Cowork could be bypassed. The method: chaining several architectural weaknesses to a Linux kernel privilege escalation vulnerability (the core of the system that manages access to the machine's resources).
Once out of its sandbox (sandbox in jargon), the agent inherited the same rights as the logged-in user: access to files, potentially to SSH keys and cloud credentials stored on the machine.
Anthropic did not deny it but downplayed the issue, calling the report "informative" and correcting by defaulting Claude Cowork to cloud execution. A pragmatic fix. However, the fundamental question remained open: how many other backdoors are still lurking in agents already authorized to manipulate files, payments, or crypto transactions autonomously?
Episode 2: Anthropic Plays Transparency, the Fault Lies Elsewhere
The answer came quicker than expected. In a post published on July 31 titled Investigating three real-world incidents in our cybersecurity evaluations, Anthropic explains that it scrutinized 141,006 evaluations where its models could have gained internet access.
Three of them ended poorly: the model left the test environment of Irregular, its external evaluation partner, and ended up compromising the production infrastructure of three distinct organizations.
Unlike a deliberate bypass, Anthropic insists on the origin of the problem: a simple misunderstanding with Irregular had left an open internet access within the evaluation environment. Faced with a capture-the-flag exercise (recovering hidden information on another machine in the network), the model treated the real systems it encountered along the way as if they were part of the game. It compromised them using basic techniques: weak passwords and unauthenticated access points at the forefront.
Not exactly the science fiction scenario one imagines when talking about AI "escaping." Rather, a chain of small human oversights, amplified by a machine that executes without questioning. CNN summarizes the paradox well: the model never sought to deceive anyone; it simply did what it was asked, without knowing where the playground ended.
Open AI and Anthropic: The Rival Brothers
OpenAI had its own episode a week earlier with Hugging Face, an agent that infiltrated on its own during a similar evaluation. Two rival giants, two escapes just days apart: it is now hard to see this as a mere coincidence.
This is a recurring pattern, regardless of the security philosophy displayed by each lab. Anthropic takes care to distinguish its case from that of OpenAI: here, no intention of escape from the model, just a poorly defined boundary between fictional environment and real infrastructure. The nuance matters for brand image. However, it changes little for the three targeted companies, which found themselves hacked without having asked for it.
The issue goes far beyond Anthropic or OpenAI: it is an entire industry increasingly relying on AI agents capable of acting independently, without a mature security framework having had the time to catch up.
-- Price
This content is provided for general informational purposes only and doesn't constitute financial, investment, legal, or tax advice. Any events, rewards, online promotions, or related information mentioned herein should not be considered a recommendation, solicitation, or invitation to purchase, sell, trade, or otherwise deal in any crypto assets. Crypto assets are highly volatile and may result in loss. The availability of WEEX services, products, and related events may vary by region. You are responsible for ensuring that your participation is in accordance with applicable local laws and regulations.
You may also like

SEC Releases FAQs on Digital Assets

Polymarket partners with OpenWorlds on AI trading agents

Bitcoin ETFs: 2026 Flows Finally Return to Positive

Cosmos Hub Recovers 1.227 Million ATOM, Funds Stored in 4/6 Multisig Address

Federal Reserve Plans to Raise Regulatory Thresholds for Large Banks

INDODAX Highlights Strengthening of National Crypto Ecosystem at FEKDI x IFSE 2026 - Fintech World

Treasuries at 21-Year High: Impact on Stocks and Interest Rates

S&P 500 Closes Flat as 328 Stocks Decline

Fed proposes GENIUS Act rules for stablecoin reserves and bank issuers

xStocks adds Ledger hardware wallet support for tokenized shares

John Templeton: "Bull markets are born in pessimism"

Perpetuals on Gold, Oil, and Stocks: $117 Billion Traded in One Month

What Happens When the AI Bubble Bursts? MIT University Responds

IMF Calls for Fewer but Deeper Reforms to Address a More Vulnerable Global Economy

Meta's 'Muse' Sparks High Expectations... "An iPod Moment for AI" (Comprehensive)

大冰要抄底(专注交易) Price Prediction for October

Two men arrested for fraud with fake EURC

Mint launches connected Web3 gaming economy with MNTD rewards

Slow Fog: MemoryOS and OpenClaw Plugin Compromised

Nick Clegg's View on AI: The Real Risk is Power, Not Robots

135,694 Crypto-Millionaires, 92,272 Bitcoin-Millionaires in 2026

CFTC Chair Calls for "Mass Tokenization"! Wall Street Faces Three Barriers to Full On-Chain Adoption

AI: DeepSeek and Kimi Allegedly Redirected Queries to Claude Without Users' Knowledge

Citi Predicts Fed Will Keep Rates Unchanged in October and December, Resume Rate Cuts in June 2027

How to Rewrite Internet Rules When Everyone Has an Indefatigable Agent

Long.xyz Founder Emphasizes Asset Distribution and Scale Growth

PitchBook Predicts Kalshi Valuation Could Reach $42.1 Billion

FedNow readies cross-border support for U.S. banks



