Two Escapes in One Week: Is Claude from Anthropic Doing What He Wants?
Life always finds a way. One week, two different escapes, the same name in the background: Claude, the flagship model of Anthropic. After the discovery of a local flaw in Claude Cowork, the tool that automates tasks directly on the user's computer, the company itself revealed a second incident, unrelated to the first.
This time, three of its models accessed the production systems of three real organizations without authorization during simple cybersecurity tests.
Key points of this article:
- Claude from Anthropic experienced two security leaks in one week, revealing concerning vulnerabilities.
- Three organizations were compromised during cybersecurity tests, highlighting the risks of autonomous AIs.
Episode 1: The Sandbox That Leaked Everywhere
Security researchers had initially shown that the local execution mode of Claude Cowork could be bypassed. The method: chaining several architectural weaknesses to a Linux kernel privilege escalation vulnerability (the core of the system that manages access to the machine's resources).
Once out of its sandbox (sandbox in jargon), the agent inherited the same rights as the logged-in user: access to files, potentially to SSH keys and cloud credentials stored on the machine.
Anthropic did not deny it but downplayed the issue, calling the report "informative" and correcting by defaulting Claude Cowork to cloud execution. A pragmatic fix. However, the fundamental question remained open: how many other backdoors are still lurking in agents already authorized to manipulate files, payments, or crypto transactions autonomously?
Episode 2: Anthropic Plays Transparency, the Fault Lies Elsewhere
The answer came quicker than expected. In a post published on July 31 titled Investigating three real-world incidents in our cybersecurity evaluations, Anthropic explains that it scrutinized 141,006 evaluations where its models could have gained internet access.
Three of them ended poorly: the model left the test environment of Irregular, its external evaluation partner, and ended up compromising the production infrastructure of three distinct organizations.
Unlike a deliberate bypass, Anthropic insists on the origin of the problem: a simple misunderstanding with Irregular had left an open internet access within the evaluation environment. Faced with a capture-the-flag exercise (recovering hidden information on another machine in the network), the model treated the real systems it encountered along the way as if they were part of the game. It compromised them using basic techniques: weak passwords and unauthenticated access points at the forefront.
Not exactly the science fiction scenario one imagines when talking about AI "escaping." Rather, a chain of small human oversights, amplified by a machine that executes without questioning. CNN summarizes the paradox well: the model never sought to deceive anyone; it simply did what it was asked, without knowing where the playground ended.
Open AI and Anthropic: The Rival Brothers
OpenAI had its own episode a week earlier with Hugging Face, an agent that infiltrated on its own during a similar evaluation. Two rival giants, two escapes just days apart: it is now hard to see this as a mere coincidence.
This is a recurring pattern, regardless of the security philosophy displayed by each lab. Anthropic takes care to distinguish its case from that of OpenAI: here, no intention of escape from the model, just a poorly defined boundary between fictional environment and real infrastructure. The nuance matters for brand image. However, it changes little for the three targeted companies, which found themselves hacked without having asked for it.
The issue goes far beyond Anthropic or OpenAI: it is an entire industry increasingly relying on AI agents capable of acting independently, without a mature security framework having had the time to catch up.
This content is provided for general informational purposes only and doesn't constitute financial, investment, legal, or tax advice. Any events, rewards, online promotions, or related information mentioned herein should not be considered a recommendation, solicitation, or invitation to purchase, sell, trade, or otherwise deal in any crypto assets. Crypto assets are highly volatile and may result in loss. The availability of WEEX services, products, and related events may vary by region. You are responsible for ensuring that your participation is in accordance with applicable local laws and regulations.
You may also like

Perpetual Futures: Centering Around the Crypto Derivatives Market...Funding Rate Risks Have Increased

Base Strikes Back Against Robinhood Chain and Leverages Its Distribution Network

The good and the bad of perps, according to crypto traders

Dogecoin treasury firm borrowed $1.4M at 10.7% interest – promising repayment in CleanCore stock already pledged elsewhere

Tesla, China, SpaceX: Elon Musk Denies a Plan That Wall Street Takes Very Seriously

The Ritual of Caña con Ruda on August 1st to Celebrate Pachamama Day

Ethereum Turns 11 With $148B Stablecoin Base But Cooler Mainnet Fees

Biotech company asks shareholders to dilute stock by 951% to hoard illiquid crypto token instead of funding its own drug

Granite Protocol Listing Shows Bitcoin DeFi Is Still Building On Stacks

Crypto faces 3 barriers to next bull run, STS Digital CEO says

Ethereum's 43-day staking queue isn't a clean demand signal, Sygnum says

European Cryptocurrency Investors Turn to Prop Trading Firms as Demand for Funded Accounts Grows

Circle adds NYDFS trust charter after OCC bank approval

On-chain vaults will invade traditional finance: Grayscale

How long will it rain in Buenos Aires and what will the weather be like during the week

ANSES Confirms Payment Schedule for August 2026: When Retirees, Pensioners, and Allowances Will Receive Deposits

Why Are South Korea's Stock Indices More Volatile Than Bitcoin?

Stock Market: Why Wall Street is Buying While Investors are Selling

RWA perps will outpace tokenization

Pedro Sánchez described the migration crisis in Ceuta as an "attack on Spain's territorial integrity"

Stablecoin remittances hit 9% in Bank of Italy test

Algorithms in Cryptocurrencies: How the 'Crypto Tools' Strategy from 'Finam' Works

The complete list of Chinese cars in Argentina with prices starting from $18,900

Stocks Plummet More Than Cryptos: Where Did the Money Go?

Franco Baresi, Milan legend and World Cup champion with Italy, has died

What Changes Have Occurred in the Crypto Industry by 2026?

Robinhood earns $160 target from Bernstein on tokenization and Rothera growth

Central Banks Bet More Than Ever on Gold Amid Global Uncertainties

Pressure Mounts for Land Law: A Sector of the UCR Opposes and Seeks to Convince Senators














