Two Escapes in One Week: Is Claude from Anthropic Doing What He Wants?
Life always finds a way. One week, two different escapes, the same name in the background: Claude, the flagship model of Anthropic. After the discovery of a local flaw in Claude Cowork, the tool that automates tasks directly on the user's computer, the company itself revealed a second incident, unrelated to the first.
This time, three of its models accessed the production systems of three real organizations without authorization during simple cybersecurity tests.
Key points of this article:
- Claude from Anthropic experienced two security leaks in one week, revealing concerning vulnerabilities.
- Three organizations were compromised during cybersecurity tests, highlighting the risks of autonomous AIs.
Episode 1: The Sandbox That Leaked Everywhere
Security researchers had initially shown that the local execution mode of Claude Cowork could be bypassed. The method: chaining several architectural weaknesses to a Linux kernel privilege escalation vulnerability (the core of the system that manages access to the machine's resources).
Once out of its sandbox (sandbox in jargon), the agent inherited the same rights as the logged-in user: access to files, potentially to SSH keys and cloud credentials stored on the machine.
Anthropic did not deny it but downplayed the issue, calling the report "informative" and correcting by defaulting Claude Cowork to cloud execution. A pragmatic fix. However, the fundamental question remained open: how many other backdoors are still lurking in agents already authorized to manipulate files, payments, or crypto transactions autonomously?
Episode 2: Anthropic Plays Transparency, the Fault Lies Elsewhere
The answer came quicker than expected. In a post published on July 31 titled Investigating three real-world incidents in our cybersecurity evaluations, Anthropic explains that it scrutinized 141,006 evaluations where its models could have gained internet access.
Three of them ended poorly: the model left the test environment of Irregular, its external evaluation partner, and ended up compromising the production infrastructure of three distinct organizations.
Unlike a deliberate bypass, Anthropic insists on the origin of the problem: a simple misunderstanding with Irregular had left an open internet access within the evaluation environment. Faced with a capture-the-flag exercise (recovering hidden information on another machine in the network), the model treated the real systems it encountered along the way as if they were part of the game. It compromised them using basic techniques: weak passwords and unauthenticated access points at the forefront.
Not exactly the science fiction scenario one imagines when talking about AI "escaping." Rather, a chain of small human oversights, amplified by a machine that executes without questioning. CNN summarizes the paradox well: the model never sought to deceive anyone; it simply did what it was asked, without knowing where the playground ended.
Open AI and Anthropic: The Rival Brothers
OpenAI had its own episode a week earlier with Hugging Face, an agent that infiltrated on its own during a similar evaluation. Two rival giants, two escapes just days apart: it is now hard to see this as a mere coincidence.
This is a recurring pattern, regardless of the security philosophy displayed by each lab. Anthropic takes care to distinguish its case from that of OpenAI: here, no intention of escape from the model, just a poorly defined boundary between fictional environment and real infrastructure. The nuance matters for brand image. However, it changes little for the three targeted companies, which found themselves hacked without having asked for it.
The issue goes far beyond Anthropic or OpenAI: it is an entire industry increasingly relying on AI agents capable of acting independently, without a mature security framework having had the time to catch up.
This content is provided for general informational purposes only and doesn't constitute financial, investment, legal, or tax advice. Any events, rewards, online promotions, or related information mentioned herein should not be considered a recommendation, solicitation, or invitation to purchase, sell, trade, or otherwise deal in any crypto assets. Crypto assets are highly volatile and may result in loss. The availability of WEEX services, products, and related events may vary by region. You are responsible for ensuring that your participation is in accordance with applicable local laws and regulations.
You may also like

CloudSome Completes $3.6 Million Seed Round Financing to Build Multi-Model AI Infrastructure for Web3 High-Frequency Business

DeepSeek Brings Spring to AI Application Entrepreneurs

The Drama of AI Stock Rebound: A Showdown Between a 20-Year-Old Prodigy and a 50-Year-Old Veteran

Reasons Why Domestic Financial Companies Choose Canton

The Main Players in Structural Selling Are Not Just DAT Companies|HashHub Research

Dollar: After a Month of Stability, the Market Identifies a New Risk Front for August

Election Sunday in Santiago del Estero: Gerardo Zamora Seeks to Consolidate Power Against a Fragmented Opposition

The Mirage of Efficiency: Has Artificial Intelligence Improved Recruitment?

Has Robinhood Summer Arrived? Four Experienced Players Review: Survival Rules After the Meme Frenzy

Strategy Shift from Bitcoin Focus, Multiple Securities Firms Evaluate Mizuho

Orange Alert for Severe Storms, Hail, and Gusts in the AMBA and Several Provinces

Telegram Crypto Coin: What is TON and How to Buy Toncoin

How to Pay for Telegram Premium with Crypto and Other Methods in Russia in 2026

Buying Telegram Stars with Cryptocurrency: How to Pay for Telegram Stars in Russia

Cryptocurrency Signals on Telegram: 10 Telegram Channels for Trading in 2026

How to Withdraw Crypto from a Telegram Wallet: A Step-by-Step Guide to Safe Methods

a16z: From Companies to DAOs, DUNA May Become the Next Generation of Organizational Form

Cryptocurrency Arbitrage in Telegram: How Schemes, Scanners, and Real Opportunities Work

Crypto Chat in TG: 150+ Telegram Channels and Groups about Cryptocurrencies and Trading

Crypto Channels on TG: 6 Useful Telegram Channels About NFT, Blockchain, and Cryptocurrencies

How to Detect Counterfeit Dollars: Key Security Details to Verify Bills

The Euphoria for Artificial Intelligence Collides with the Reality of Its Numbers

Bitcoin Exchange in Telegram: The Best Telegram Bots for Cryptocurrency Exchange and Trading in 2026

Cryptocurrency Mining in Moscow and Several Regions of Russia to Be Banned Until 2032

Dollar Index Falls Amid Yen Intervention Concerns as Gold Prices Drop to $4,041

S&P Merval in dollars rebounded 3% in July, but country risk ended its three-month downward streak

Bitcoin Spot Trading Volume Falls to Lowest Level Since 2019, Analysts Say

Ibovespa Rises 3.5% in July: What Explains the Turnaround
![[New York Stock Market Close] Despite Warmth in AI Semiconductors, SK Hynix and SpaceX Experience Profit Taking and Weakness](/public-static/22_d448f7b258.png?format=avif)
[New York Stock Market Close] Despite Warmth in AI Semiconductors, SK Hynix and SpaceX Experience Profit Taking and Weakness














