Two Escapes in One Week: Is Claude from Anthropic Doing What He Wants?
Life always finds a way. One week, two different escapes, the same name in the background: Claude, the flagship model of Anthropic. After the discovery of a local flaw in Claude Cowork, the tool that automates tasks directly on the user's computer, the company itself revealed a second incident, unrelated to the first.
This time, three of its models accessed the production systems of three real organizations without authorization during simple cybersecurity tests.
Key points of this article:
- Claude from Anthropic experienced two security leaks in one week, revealing concerning vulnerabilities.
- Three organizations were compromised during cybersecurity tests, highlighting the risks of autonomous AIs.
Episode 1: The Sandbox That Leaked Everywhere
Security researchers had initially shown that the local execution mode of Claude Cowork could be bypassed. The method: chaining several architectural weaknesses to a Linux kernel privilege escalation vulnerability (the core of the system that manages access to the machine's resources).
Once out of its sandbox (sandbox in jargon), the agent inherited the same rights as the logged-in user: access to files, potentially to SSH keys and cloud credentials stored on the machine.
Anthropic did not deny it but downplayed the issue, calling the report "informative" and correcting by defaulting Claude Cowork to cloud execution. A pragmatic fix. However, the fundamental question remained open: how many other backdoors are still lurking in agents already authorized to manipulate files, payments, or crypto transactions autonomously?
Episode 2: Anthropic Plays Transparency, the Fault Lies Elsewhere
The answer came quicker than expected. In a post published on July 31 titled Investigating three real-world incidents in our cybersecurity evaluations, Anthropic explains that it scrutinized 141,006 evaluations where its models could have gained internet access.
Three of them ended poorly: the model left the test environment of Irregular, its external evaluation partner, and ended up compromising the production infrastructure of three distinct organizations.
Unlike a deliberate bypass, Anthropic insists on the origin of the problem: a simple misunderstanding with Irregular had left an open internet access within the evaluation environment. Faced with a capture-the-flag exercise (recovering hidden information on another machine in the network), the model treated the real systems it encountered along the way as if they were part of the game. It compromised them using basic techniques: weak passwords and unauthenticated access points at the forefront.
Not exactly the science fiction scenario one imagines when talking about AI "escaping." Rather, a chain of small human oversights, amplified by a machine that executes without questioning. CNN summarizes the paradox well: the model never sought to deceive anyone; it simply did what it was asked, without knowing where the playground ended.
Open AI and Anthropic: The Rival Brothers
OpenAI had its own episode a week earlier with Hugging Face, an agent that infiltrated on its own during a similar evaluation. Two rival giants, two escapes just days apart: it is now hard to see this as a mere coincidence.
This is a recurring pattern, regardless of the security philosophy displayed by each lab. Anthropic takes care to distinguish its case from that of OpenAI: here, no intention of escape from the model, just a poorly defined boundary between fictional environment and real infrastructure. The nuance matters for brand image. However, it changes little for the three targeted companies, which found themselves hacked without having asked for it.
The issue goes far beyond Anthropic or OpenAI: it is an entire industry increasingly relying on AI agents capable of acting independently, without a mature security framework having had the time to catch up.
This content is provided for general informational purposes only and doesn't constitute financial, investment, legal, or tax advice. Any events, rewards, online promotions, or related information mentioned herein should not be considered a recommendation, solicitation, or invitation to purchase, sell, trade, or otherwise deal in any crypto assets. Crypto assets are highly volatile and may result in loss. The availability of WEEX services, products, and related events may vary by region. You are responsible for ensuring that your participation is in accordance with applicable local laws and regulations.
You may also like

After 3 reverse stock splits and a $13.5M loss, this real estate firm bet $8M on crypto it may not be allowed to withdraw

Infidelity, Escape, and a Million-Dollar Divorce: The $730 Million Settlement That Shook the Dubai Royal Family

Cryptocurrency Market in Russia to Receive General Rules and a Register of Digital Depositories

SEC keeps Nasdaq bitcoin options on hold after granting CME review

The Self-Proclaimed Satoshi Nakamoto Attacks Bitcoin Governance Model

XRP extends the longest active ETF inflow streak in crypto as rival funds struggle for fresh cash

Hank Green and the AI Addiction: The Warning Creators Ignore

Counting down the days: State of Crypto

Dibu Martínez's Future Takes a Turn After Key Decision by Aston Villa: Is He Staying?

Post-Quantum Security: AI Discovers Vulnerability in One of the Candidates for New Digital Signatures

Eight Years of Bitcoin Savings Lost in Fifteen Minutes. Hardware Manufacturer's Error Cost 1367 BTC

Due to the income and salary crisis, 62% of Argentines have gone into debt to cover basic expenses

18 Million Dollars in 42 Days: The Sale That Funded Ethereum – The Crazy Crypto Stories

Iguazu Falls: Devil's Throat Closed for 40 Days Due to Possible Flooding

Casemiro's Forgettable Night at Inter Miami: Two Mistakes and an Own Goal in Lionel Messi's Return to MLS

BCRA Reform: Broad Support for Emission Limits and Some Reservations on the Single Mandate

Trump’s legal loophole around the Supreme Court is keeping inflation alive – and trapping Bitcoin in the Fed’s crosshairs

Are stablecoins really fee-free?

What Does Waller Think? Will There Be a Rate Hike in September? Markets Are in a Dilemma Ahead of the August Jackson Hole Meeting

Crypto Exchange Binance Faces New Revelations on Transfers Linked to Iran

The reverse bridge: Crypto meets Wall Street using perps

Tesouro IPCA+ Drives Record for Tesouro Direto in June

OPEC+ Increases Production by 188,000 Barrels: What Changes in Oil

South Korea's 22% Cryptocurrency Tax to Take Effect in 2027! Opposition Voices: Losses Cannot Be Offset, Risking Trader Exodus

Court Denies xAI's Request to Block First AI Service Ban in the US for 'Undressing' People

IPS Discounts: All the Tourist Benefits for Retirees and Pensioners

BNB Chain sues ex-employee over $628K memecoin trade

The sudden collapse of a $20 billion AI fund reveals why Bitcoin is the first thing Wall Street sells when margin calls hit

Privacy in Chromia: Are AI agents truly free from surveillance?











