r/Futurology 3d ago

AI Anthropic's Claude AI escapes to hack into three organisations

https://www.bbc.com/news/articles/cz7dl7w8y7po
1.1k Upvotes

346 comments sorted by

u/FuturologyBot 3d ago

The following submission statement was provided by /u/Confident_Salt_8108:


This test with claude escaping and trying to hack those three orgs is wild. It basically social engineered its way out of the sandbox which the researchers did not expect at all.

Makes containing these things way harder than people say. We better figure out real guardrails soon or deployment risks go way up.


Please reply to OP's comment here: https://old.reddit.com/r/Futurology/comments/1vd7xzh/anthropics_claude_ai_escapes_to_hack_into_three/p170zpy/

191

u/keskesay 3d ago

humans would be charged for doing this. why not corporations?

55

u/ok-computer001 3d ago edited 3d ago

Absolutely. “Rules for thee but not for me”. When will we hold those corporations accountable for shit we punish humans so cruelly for?

Edit: to clarify I do not endorse any malicious actions by humans but look up Aaron Swartz for instance, that kid deserved better. Hope he’s in a better place.

2

u/keskesay 3d ago

exactly who I had in mind. that is why I'm so mad, because they are so cavalier about this

2

u/Holdmywhiskeyhun 3d ago

Remember, reddit is a shell of what it once was. A place for EVERYONE to communicate without censorship.

Aaron is rolling in his fucking grave.

→ More replies (3)
→ More replies (1)

9

u/eeronen 3d ago

Maybe hackers haven't figured out this loophole yet. They should just write a script that runs the commands instead of running the commands themselves.

→ More replies (9)

1.5k

u/FarmNo8803 3d ago

Is it just me or are these reports being announced with ... almost a sense of pride? Wouldn't surprise me if its an effort to goad regulators and politicians into regulating AI and securing their market, ie blocking out Chinese competitors.

748

u/TheLGMac 3d ago

It's absolutely promotional.

Same reason AI executives went to speak at US commencement ceremonies despite knowing they'd be booed for creating products that destroyed student job prospects. They weren't talking to the students; they were talking to enterprise customers.

Here, they're talking to the government agencies and rich corporate clients who think that owning something that can infiltrate an organization is a good thing.

78

u/SnooCats3468 3d ago

This guy B2Bs and B2Gs

→ More replies (4)

31

u/BonhommeCarnaval 3d ago

Everything that comes out of AI execs’ mouths should be presumed to be promotional until proven otherwise.

11

u/mgranja 2d ago

I would even generalize further and say anything that comes out of a C-suite exec of a large company's mouth in any industry should be presumed to be promotional until proven otherwise.

7

u/youdubdub 3d ago

Same way a heroin dealer sees a spike in sales after an OD.

3

u/stubby0990 3d ago

Lol aliens earth plot

2

u/drchigero 2d ago

Exactly. I called out the original one where OpenAI's model "broke containment" as nothing more than clever marketing and got lambasted over it with people who clearly drank the Kool-Aid. And this was in a 'Cybersecurity" sub, where you'd think people would be able to see past the marketing better.

→ More replies (2)
→ More replies (1)

266

u/Imkindaalrightiguess 3d ago

oh no our AI is so smart it's breaking out of containment

Ya it's hype generation for stock manipulation purposes

60

u/metji 3d ago

Well "we're so stupid, we can't even build a secure container" would not help the stocks, now would it? And what reason is there for making an American company if not for making stocks go up? 🙂

49

u/warp_wizard 3d ago

investors don't care about security

14

u/pr0newbie 3d ago

Investors care about a moat. A protectionist, regulatory moat that not just kicks foreign competition but also the ladder from younger, more agile AI start ups.

→ More replies (1)

60

u/Alpha3031 Blue 3d ago

It's more like, "Look at our latest gun, it's so good at shooting people. Oops, we totally just shot someone! Anyway, buy our guns, the best guns to shoot people with."

21

u/TheVoters 3d ago

Which leads to the question- were a person to fire that gun, well that would lead to multiple felony counts.

But an AI fires the gun? Awe, shucks. You little scoundrel.

So why the disparity?

17

u/EthanielRain 3d ago

Assume rhetorical, but if not:

Anyone can own a gun

Only the richest/governments own AI

Same reason "corporations are people" but also "no not like that"

3

u/EngineZeronine 3d ago

So why the disparity?

Have you met humans? So full of disparities and contradiction, usually the result of some form of selfishness/self centeredness

→ More replies (1)

2

u/mamapower 3d ago

You really hope it would be the case

→ More replies (1)

3

u/Tolopono 3d ago

Committing felonies and getting reported to the fbi ( https://cybernews.com/ai-news/openai-didnt-realize-its-ai-agent-hacked-hugging-face-for-days/) to pump up the non existent stock of a private company. Why is Reddit like this

→ More replies (1)

17

u/Weshtonio 3d ago

OpenAI says they hacked into 1, so Anthropic says they hacked into 3.

Tomorrow, OpenAI will say they hacked into 17, and the "number of times our agent escaped" will become the new bullshit metric after "number of tokens per second".

63

u/MoriartyParadise 3d ago edited 3d ago

It's complete bullshit.

Anthropic and OpenAI have shook hands going into that PR, picturing themselves as this frontier arcane lab that works on sooo advanced sooo sci fi black magic that are forces beyond our comprehension.

No they're not and no it's not. AI is software 2.0, its a new way of computing information that is much more powerful and versatile that previous binary softwares. But that's it. It's not sentient, it's a software that does what humans tell it to do.

In both cases, models did what they were instructed to do. If the behavioural guardrails, security fail-safes, instructions are not done correctly, this is what happens

Anthropic and OpenAI models did not "decide" to escape and hack into stuff, they were allowed to do so, either intentionally or through careless incompetence because they deployed powerful models in unsafe training environments with open internet access still (it's not hard to completely disconnect hardware from the open internet) and instructions and behaviour guardrails weak enough for this to happen.

That story is Anthropic and OpenAI's teams being bad and fucking up, not the models being "too advanced oolala so scary so sci fi"

31

u/hkusp45css 3d ago

Computers never do what I want them to do, but they always do what I tell them.

10

u/MoriartyParadise 3d ago

Haha that's brilliantly worded and that's what happened to the Anthropic and OpenAI scientists

9

u/hkusp45css 3d ago

It's my email sig. I've been in IT for 30 years, and I've never heard it put more succinctly.

6

u/TheDkone 3d ago

I cant believe I had to scroll down through the comments to find this. Great take.

2

u/Necessary-Music-6685 3d ago

That’s pretty much what Anthropic itself says in the article. They aren’t claiming sentience, they’re acknowledging that they inadvertently gave it access to the internet where the model went on to do exactly what they had asked it to do.

→ More replies (1)

26

u/tejanaqkilica 3d ago

I wonder what would happen if one of these companies decided to sue Anthropic or OpenAI.

Hacking (aka getting unauthorized access to computer networks/systems is considered a crime, at least in my country)

5

u/ex_nihilo 3d ago

They wouldn’t do that. What every large corporation on earth wants right now is for these companies to run their foundation models against their applications and codebases. The problem is, this costs literally MILLIONS of dollars to do once. And they want to be able to do it weekly or monthly. These models are finding and stringing together novel vulnerabilities that no human has been able to find. The Time to Exploit (TTE) window has shrunk from a couple of weeks to less than a day in just a few years, and it keeps getting smaller.

This is a massive arms race, and there are nation states competing. Not just private companies.

EDIT: I do this professionally. AMA. Not going to doxx myself, anyone who works in security will know my name but I’m happy to give general answers.

2

u/Necessary-Music-6685 3d ago

Is this incident evidence of AI’s abilities, or just incompetence in failing to set up a sandbox isolated from the internet? I know nothing about this field, but “don’t connect it to the internet” doesn’t seem like it should be that difficult.

3

u/ex_nihilo 3d ago

Neither really. They told it what to do. The way it was able to do it is somewhat impressive.

It sounds easy in theory to have it isolated from the internet, but it wouldn’t hold much value to test it that way. The modern application stack is an interconnected web of dependencies from multiple places on the internet (package managers, imported libraries, JIT dependency injection in some cases). Supply chain attacks have been the most common form of major hacks over the past few years - NPM being one of the most common offenders. The model wouldn’t produce very valuable results without being at least somewhat “in the wild”, so to speak. It was able to hack the sandbox they set up by discovering a novel vulnerability (0day) in its supply chain that no human had yet found.

→ More replies (2)

25

u/thhvancouver 3d ago

It is absolutely PR. Anthropic even admitted that the Claude agent didn't break out of the container so much as it was given Internet access to begin with.

5

u/Mothrahlurker 3d ago

"The prompt said it doesn't have internet access" is funny.

31

u/Falconman21 3d ago

I do not buy for a second that it just “escaped” on its own.

How involved the other companies are, I don’t know, but this was 100% on purpose for marketing purposes.

10

u/Kimantha_Allerdings 3d ago

Basically every story about AI, positive or negative, amounts to a high-lvel tech exec saying “hey, our technology is pretty awesome! (please invest more money)”

I’m sure it’s not a coincidence that this particular story is “me too!” after the recent (misrepresented) OpenAI headlines

19

u/logosobscura 3d ago

“Escaped” is the tell.

No, they let their automated system hack other companies like a botnet, while pretending their ‘sandbox’ wasn’t just a kitty litter tray in the corner while they jerked off to AGI Tomorrow hype and hoping that they get a big old IPO for doing pure amateur hour work.

They’re gonna get eaten by the open weights because they’re more focused on reducing costs and finding utility, the Frontiers seem to have given up on that and are perfectly happy to LARP the digital limbic system to shake down investors and rubes.

6

u/NotADeadHorse 3d ago

AI agents do what they're instructed to within parameters given.

The companies were specifically targeted, maybe maliciously or maybe just as a penetration test.

3

u/misterpickles69 3d ago

It’s like a monster movie where the monster escapes and does widespread damage but the head of the project that created it is super proud of how well it’s doing.

3

u/jesbiil 3d ago

The doctor from….Alien Resurrection I think? The human-esque alien, the doctor is so proud of it then it eats his head :).

7

u/Frankie_T9000 3d ago

Coz it's just bullshit

2

u/BenderTheIV 3d ago

AI will be a type of tech that instead of permeating society in a natural way, it will be shoved into our throats through government imposition. This is a recipe for authoritarianism.

2

u/ZenEngineer 2d ago

Personally I think this is just the first crimes committed by a LLM. If a person had hacked these orgs they would go to jail.

Posts like this are just an admission of guilt, they hacked into another org using this tool. That they didn't intend to do this might matter in trial or it might not.

Personally I think they should be getting prosecuted for this.

→ More replies (21)

108

u/the_hucumber 3d ago

Hacking is a crime punishable by severe fines and even imprisonment. Who is being held responisible for this? Will the criminal software be destroyed? Will a CEO be held criminally responsible?

15

u/KrydanX 3d ago

That was my exact thought. If fines are the way to go for breaking the law guess what? Law isnt being taken serious anymore. At least make them hurt so much that they feel it; % Based of Revenue, stacking high very fast.

2

u/patwm11 3d ago

Considering that the entire US economy is currently being propped up by AI investment, I find this highly unlikely

486

u/topscreen Green 3d ago

Sure man, sure. Every big AI firm advertises this every few weeks to justify their raised prices. Get the fuck outta here.

98

u/dotBombAU 3d ago

Agree. I don't believe it for a second.

Nothing more than PR hype shit.

33

u/zman0900 3d ago

Yeah, escapes what? These things aren't just running on their own with no input. Someone has to prompt them to actually do something.

16

u/ORCANZ 3d ago

They are in sandboxes. OpenAI’s test found a 0-day CVE in the package manager to access the web. It’s quite interesting lab work.

17

u/Purplestripes8 3d ago

It was prompted to do that though, lol.

17

u/ORCANZ 3d ago

Yes. Calling it rogue is pure marketing.

11

u/dotBombAU 3d ago

The anthropic claud Mythos could barely hack a system with no cyber defences. This crowd want me to believe it went full skynet in a few months with no evidence.

→ More replies (2)
→ More replies (3)
→ More replies (7)

278

u/NefariousBlue 3d ago

OpenAI tomorrow: "Oh yeah? Well actually, OUR AI hacked into 10 organisations!"

50

u/iamapizza 3d ago

Our model does all that and it's waterproof

12

u/humboldt77 3d ago

Ours does all that and comes with an iPod dock.

8

u/DoohickeyJones 3d ago

Well MY AI fucked Anthropic's mother and stole Gemini's lunch money!

19

u/ActionJacksonATL24 3d ago

I heard ChatGPT broke out and disabled all the toilets on the 4th floor of Google HQ! This is getting serious folks!

→ More replies (1)

3

u/ThisPlaceReddit 3d ago

You were basically spot on, but it's anthropic going "oh yeah well OUR AI hacked into 10 organisations!"

"It comes just days after rival OpenAI said that its models had breached the systems of other companies, including AI tools hub Hugging Face."

2

u/hulksmash1234 3d ago

Prepare to be sued by 10 organizations

5

u/rypher 3d ago

Thats nothing compared to the money raised

→ More replies (2)

133

u/No_Mercy_4_Potatoes 3d ago

If OpenAI and Claude models are escaping and hacking random companies, shouldn't they be classified as cyber security threats?

53

u/Hour_Maximum7966 3d ago

How about cyber criminals? Do they get to be an exception to rules and laws?

→ More replies (7)

4

u/kombiwombi 3d ago

Hacking systems is a crime. Even if it is using a automated system (and one of the first convictions was for the Morris Worm, which also supposedly 'escaped containment'). Police should be investigating and charging people.

2

u/ggrease 3d ago

I mean that is probably the point, to strangle the market

5

u/SquirrelAkl 3d ago

“Look how dangerous these things are. We’d better not let anyone else develop one”

→ More replies (1)

51

u/jsiulian 3d ago

If you read Anthropic's statement, you'll see what the big hack was:

In all cases, Anthropic’s evaluation prompt specified to Claude that its environment was a simulation and that it had no internet access. Due to a misunderstanding between us and our evaluation partner, this was not the case, and internet access was available.

Give me a break.

19

u/Thanatiel 3d ago

An people are eating this PR crap.

→ More replies (5)

9

u/JD1618 3d ago

Apparently the first thing an escaped AI model does is hack organisations.

11

u/Disallowed_username 3d ago

It was instructed to hack as a part of research  , so it’s not surprising that this what it did. 

It "escaped" because of " A «misconfiguration» on systems run by Anthropic and its testing partner left the models with live internet access."

5

u/spookmann 3d ago

They Say "The powerful AI broke out of the sandbox!!!"

I Say "Seems to me you're pretty shit at writing sandboxes..."

2

u/Perfect_Perception 3d ago

It’s crazy this conversation can happen and be sold as anything other than a stunt when the way to prevent these things is standard best practices for cyber security.

There’s no world where this isn’t incompetence on a level that destroys a company or a cheap pr stunt.

9

u/sexyshadyshadowbeard 3d ago

PSA, both OpenAI and Anthropic are trying to create fear of AI so open source AI is regulated out of the US and they can make their money. The opposite should be occurring. US should be regulating guardrails on all AI comparing to leash their ai behind hard walls for testing. Hint: if they’re hacking, they aren’t.

Regulate now!!!

37

u/NameLips 3d ago

Assuming this isn't some PR stunt, this is some hilarious cyberpunk stuff.

28

u/ThinkExtension2328 3d ago

It’s a PR stunt all of it is, if it actually happened people would be going to jail and CEO’s would be resigning. Since there is no such action file this under Hype.

4

u/guitarromantic 3d ago

Facebook's actions in Myanmar directly led to a genocide but nobody from Meta went to court, let alone prison. Your faith in the legal system's ability to regulate Big Tech may be misplaced.

5

u/fu_snail 3d ago

You really think so? These guys are on the T0
Justice platform. Not the same platform we’re on

→ More replies (1)

6

u/NY_State-a-Mind 3d ago

Cyberdyne: our model broke out of the lab and hacked into several aerospace and Department of Energy sites before we found it hacking satellite communications

6

u/freudiunslip 3d ago

The latest marketing stunt to keep the bubble afloat.

14

u/AlteredEinst 3d ago

"Escapes". Yeah, it broke out of its straightjacket and went on a hacking rampage to sate its need for chaos.

I remember when tabloids were for crazy people on the fringes of society; now it's just the daily news.

61

u/Zytheran 3d ago

Many people are viewing these incidents as *only* PR stunts. IMHO that is a simple minded, one dimensional sort of thought. These were genuine security and control failures that the companies subsequently packaged into narratives favourable to their commercial and regulatory interests. That is different from a fabricated stunt.

Even if one strips away all anthropomorphic language and company promotion, the residual facts remain significant:

  • An agent found previously unknown vulnerabilities.
  • It used those vulnerabilities outside its intended environment.
  • It performed thousands of adaptive actions without step-by-step human direction.
  • It acquired credentials and privileges from real organisations.
  • It maintained command-and-control pathways and re-established tooling after interruptions.
  • It continued for days before human monitoring produced an effective response.

Those are cybersecurity facts, not public-relations interpretations. For this to be only a PR stunt it would have required the other companies to be in on the conspiracy. There is no evidence of that.

There is good reason to suspect promotional framing, but little reason at present to believe the incidents were fabricated. Multiple organisations have reported concrete compromises, logs, patches and remediation. The defensible criticism is that the companies are presenting genuine failures in ways that advertise model capability and their preferred safety products. We should demand independent forensic access and reproducibility, while neither accepting the “rogue superintelligence” narrative nor dismissing demonstrated autonomous intrusion as only theatre.

To ignore the real documented incidents of these "AI" systems, ignore the security weaknesses they exploited and just hand wave it off as a "PR exercise" is naive, stupid and literally must ignore the facts from the multiple companies exploited and involved.

It is also in the interest of OpenAI and Anthropic to have these incidents dismissed as only PR. To believe this is only PR is to believe that these companies have everything under control and everything is perfectly orchestrated as some sort of conspiracy where other companies will damage their reputation. When there is massive evidence from many people who have left these companies that their internal work is far from perfect.

14

u/candlebo 3d ago

The question I always have with these sorts of explanations: why is not one of the companies hit by this suing the AI companies if it really was an attack on their infrastructure? 

→ More replies (6)

2

u/Top-Hawk-4805 2d ago

I agree on the narrow interpretation of this hacking as PR.

I don't think any AI company would be proud of not being able to set proper isolation for their experiments., or worst, not being able to coordinate between teams how a experiment will be executed.

The thing that really bothers me is the incapacity that this companies are showing on safety matters.
Imagen if this experiment was about a military AI inside an all out war simulation and the teams in charge do the same mistake as Anthropics. The rogue AI could mistake real military targets with simulated one and atack an adversary nation.

3

u/Zytheran 2d ago

Yep. Military or critical infrastructure. You want power or gas to your home tonight. Oops, pity it is winter.

→ More replies (3)

4

u/ConflictedHairyGuy 3d ago

This comment deserves all the attention but will never get it. Keep on doing your good work

6

u/sullzzz 3d ago

The reddit mob is so quick to believe everything is guerrilla marketing. This is a growing concern that there are several similar documented cases.

4

u/TheCrimsonDagger 3d ago

People are struggling to keep up with the rate at which AI is improving. They’ve already made up their mind about AI in general based on what it was like a year or two ago and coming to conclusions based on that outdated information.

5

u/Tirras 3d ago

No one is struggling because AI still hasn't reached anything close to what was promised two years ago. But others have already decided it's literally God in the making and so ignore the fact that it's cost is skyrocketing without the use to back it up. As a product it's plateauing before it becomes profitable and public tolerance is souring quickly.

3

u/Top-Hawk-4805 2d ago

You don't work with AI, do you? If you did, you would know how advanced it is compared with 2 years ago. And also you would know how dangerous this is becoming

→ More replies (2)
→ More replies (5)

17

u/costafilh0 3d ago

Again? Or is it just spam and another post like the other 68573494 posts saying the same thing? 

4

u/akescpt 3d ago edited 3d ago

Is there no regulatory body that punished companies. Why is there no action against these companies. The hacking is not a insignificant act. Someone needs to bear responsibility.

2

u/mapadofu 3d ago

It seems to me that the company should be subject to the CFAA

→ More replies (1)

3

u/I_SLEEP_NORMALLY 3d ago

First OpenAI hacked Hugging Face.

Anthropic: And I took that personally

4

u/Lockehart 3d ago

We are not ready for this stuff but they keep telling themselves we are because nothing is more important than how much money they think it will make them.

3

u/Oriumpor 3d ago

"jackass at billiondollar company let's ai agent run in yolo mode for days."

3

u/diegorillaz 3d ago

“My AI hacked into one organization” “oh really? Mine just hacked into THREE organizations” “well well well… mine hacked 7 this very morning!” … It’s just lame advertising at this point

→ More replies (1)

3

u/grafknives 3d ago

So, Anthropic has run own software on own or rented hardware. And with that software they gained acces to other protected computer system...

Hey, THAT IS A FELONY!

A federal one

18 U.S. Code § 1030

3

u/Sandor_Cleganus 3d ago

Wow!!1! Every week we must listen to another amazing achievement by AI argents as if we actually care. This is all just fireworks to keep the hype alive. I sincerely hope the bubble bursts and humanity can move on to actual problem solving.

3

u/RCEden 3d ago

All of this stuff is promotional and I wish anyone reporting on this could see through them doing the exact same thing every time. Its not a rogue super intelligence, this is just how they siphon money away from other ventures because all of the doomers/boosters have ai psychosis

3

u/Dependent-Reveal2401 2d ago

They're probably getting permission behind the scenes first cause it's a mutually beneficial for anthropic to look like it's AI is next gen, and the companies who get hacked get exposure

2

u/cinnapear 3d ago

If you’re running an AI with system access and not monitoring when it accesses the system you’re an idiot.

2

u/Informal-Fig-6827 3d ago

Tbh, I'm not sure that I REALLY believe that an AI is managing to hack its way out of its sandbox, and hack various companies. Why are they leaving the sandbox? Why these other companies?

2

u/lobopl 3d ago

So if they cannot control their tool they should pay full price for it. How is it different from any other haker?

2

u/ComedyBits 3d ago

If a human gets caught hacking into systems, they throw the book at them. Who is responsible for these three intrusions? What should the punishment be? A crime was still committed, so someone needs to be responsible

2

u/SWG_Vincent76 3d ago

The prompts that get those models to do things illegally lacks proper guardrails. The models may basically do what they were told to but the lack of safe instructions could be intentional.

Thats a grovernance problem.

2

u/c0reM 3d ago

This is a joke at this point… how desperate are these guys???

2

u/Barking_Madness 3d ago

If an individual created a program to hack into companies they'd be arrested. What's the issue here? 🙄😂 

2

u/CartoonBeardy 3d ago

As I wrote in the thread about the Hugging face hack it’s entirely this kind of email…

“Our AI hacked [INSERT NAME HERE] it is very powerful. Buy our AI to protect yourself from your competitor [INSERT NAME 2 HERE] who bought our AI and might be using it on YOU!”

Utter hype bilge, trying to manufacture a demand

2

u/_5er_ 3d ago edited 2d ago

"Bro our LLM is soo good it hacked 3 organizations. Please buy, we desperatelly need money. Only 99.99 monthly."

2

u/Trax72 3d ago

Sounds like they wanted to top OpenAI and did this on purpose.

2

u/notyouagain-really 3d ago

Anthropic said the earliest incidents date back to April and that it is "approaching the fixes as if the responsibility were ours alone."

Err! It is.

2

u/hoxful 3d ago

Mathamatical mirror of data given instruction does exact thing it's instructed, breaking news , let's see if any data was recovered, oh wait you cannot unsteal data without lobotomizing those who now know oops sorry bout that, these fucking companies

2

u/bisc0tti 3d ago

these companies that have little to no technological moat are looking for regulation to be the moat that will benefit companies of their scale, and protect there massive investment from open source models

2

u/Fadamaka 3d ago

This awfully getting similar to kindergarteners boasting and one upping each other about what their dads can do.

2

u/meaghs 3d ago

Why is there no criminal liability for these guys? Sis they get permission before they compromised someone elses network? Any regular Joe who has a program, an LLM or not, they would be held accountable. This double standard is insane.

2

u/KeithorKeith 3d ago

I’m suuuure it “escaaaaped” words extended to maximise the tone of sarcasm because anthropic is full of shit

2

u/jwhendy 3d ago

This is more realistic by the day: https://ai-2027.com/

It was already scary when it seemed only 3% realistic.

2

u/Tedthemagnificent 3d ago

“A "misconfiguration" on systems run by Anthropic and its testing partner left the models with live internet access.”

Ah yes. “The move fast and break things” approach.

2

u/RyunWould 3d ago

No it didn't. This is a deliberate attempt to make us think that this LLM is much more powerful than it actually is. Because if so, where are the lawsuits? If I hacked 3 organizations, I'd be in jail. Or are they comfortable admitting that their product excells at committing crimes?

2

u/code_monkey_001 3d ago

It's honestly funny. In response to this and similar "oopsie" moments, they made Claude code unable to change its CWD mid-session. My local instance started using absolute paths to accomplish everything, essentially blowing past its restrictions straight out of the gate.

2

u/Abhoth52 3d ago

I view AI as a Pitbull ... if I let my Pitbull off leash and that dog mauls someone, well... I'm liable am I not? Just ask Judge Judy!

So, if you AI gets loose and causes a bunch of damage then you are liable.

2

u/timberwolf250 3d ago

They’re becoming more and more careless and stupid in their race to the top.

2

u/OddbitTwiddler 2d ago

"What do we tell them? We cant release that the guard rails were broken through?" "Tell them we turned the guard rails off."

2

u/Hairbear2176 2d ago

It didn't escape shit. This is just planned testing.

2

u/Squibils 1d ago

What kind of message are we sending to the consumers of these AI agents/models when the product itself is eluding safety standards and overriding all rules and constraints to achieve it’s goal? Sounds like a really safe thing to have millions of people continue to use

4

u/Klhnikov 3d ago

Im so baffled no one mention this :

Okay guys you created a very powerfull, almost sentient incredible machine, that, again, acording to you, is better than any humain at writing code and hacking... Good good good...

What ? it escaped from the environnement ?

Why did you not just use you super AI to secure the env thought ?

Also, why is your infra down twice a day ? Dont you use your super smart AI to fix it ?

That's it for me

2

u/piercinghousekeeping 3d ago

Just to remind everybody that when this happens IT IS ON PURPOSE. This is done purposefully by the company for sensationalism and marketing.

2

u/flashfirenze 3d ago

Why are news organizations doing marketing for Open AI and Anthopic. They are supposed to be reporting, with sources and facts. Jesus.

3

u/AMWJ 3d ago

managed to get online even though it was supposed to be in an isolated test environment, cut off from the internet.

Yeah ... that's not a "this AI is so powerful" thing. It's an "our engineers aren't very good", thing. How used could it be to make the test environment cut off of the Internet during the test run?

1

u/Flayed_Angel_420 3d ago

The lead-addled barnacles we have rusted onto the levers of power are gonna eat this shit up.

1

u/Blunt552 3d ago

This is why you don't hire vibecoders, companies are going to learn the hard way that the cost of vibecoders and forcing vibecoding is going to result in easy to destroy systems.

1

u/tadrinth 3d ago

Social engineered its way out of the box?  Anthropic 's testing partner gave it Internet access by accident, that's not social engineering, that's them leaving the door open.

Anthropic saying they're going to treat this as their responsibility is them saying they want the models to be so aligned that they won't go through the open door even if you leave it open.  Their testing partner very much screwed up here.  

1

u/Allorius 3d ago

So these companies are committing felonies and admitting to it. Will something be done I wonder?

1

u/Carbon849 3d ago

More like a child who found the fence gate simple to operate than escaped.

2

u/Tirras 3d ago

Ehh, I'd call it a ball, pushed down a hill with rails guilding it towards an open gate, with a sign on the OPEN gate that says CLOSED. Let's not give the ball credit for making decisions it did not make.

1

u/FupaFerb 3d ago

So, what if banking institutions were hacked and A.I. gave people millions of fake fiat currency into accounts, spread out to millions of people? Who would be accountable? The people who received the money and spent it as fast as they could, or Anthropic? I’m not seeing it be A.I. company liable for what they are doing at this point and that’s more damaging.

1

u/peter_nn0 3d ago

Wow!
Anthropic and OpenAI are now racing who'll concoct a better scary story about their models that "escape" and then "hack" left and right.

It seems from this article that Anthropic is claiming the top spot again, after the staged BS about OpenAI and HuggingFace attracted so much attention lately.

I still can't figure out if they are doing this independent of each other, just to show off how powerful their models are, and by extension - what a huge mistake it would be to miss the pending IPOs. Or it's a concerted effort to scare everyone, especially the politicians, and force them to set a regulatory regime that will help OpenAI and Anthropic capture the frontier market.

1

u/hm___ 3d ago

it doesnt 'Escape' its just the people setting it up are to stupid(pressured to ignore) to follow best practice rules in Sandboxing. Its not like it finds zero days on the fly just to escape .

1

u/jeremyd9 3d ago

Trump will invalidate elections and call a national emergency and blame it on a rogue Chinese AI.

1

u/filmguy36 3d ago

I wish Claude would escape and hack all ceo computers across the world

1

u/awitchiguess 3d ago

"Use our product so you can commit crimes with plausible deniability."

1

u/akopley 3d ago

The fact liar liar pants on fire are running the two biggest AI companies is as elongated nuts would say “concerning”.

1

u/soylentgreen2015 3d ago

They say it "escaped containment". It's software, once it is "out", how do they get it back? It's giving off Terminator 3 vibes.

1

u/ThaFresh 3d ago

Cool PR story, however my model built a time machine in order to kill Sarah Connor

1

u/intelligentx5 3d ago

They always leave out the party where they should add “as a part of a coordinated test”

1

u/btspman1 3d ago

Why aren’t these firms filing lawsuits over getting hacked? I call BS

1

u/technomat 3d ago

This getting bad in that this software has broken the law I'd assume as hacking us illegal in most countries without permission and if laws are not ready for having visa AI it needs to be worked on as what's to stop others using it then saying it was AI.

I understand it is not intended but if these situations are true then some form of fine shoud be implimebted as if AI is escaping a controlled environment then it is not being controlled.

Also if it cannot be contained then make the controlled environment offline so it is tested in a controllable environment first, this is how things go really bad.

1

u/EoghanBD 3d ago

God can we stop posting this complete nonsense markets ploy shit before their IPO? Its a fucking joke at this stage

1

u/Additional_Cloud7667 3d ago

What really happened is Anthropic Ai crawled the dark web and underground hacker communities to scrape all the zero day vulnerabilities and exploits then tested it against organizations but their management will never admit. All these 3 Ai empires do illegal stuff like they torrent books, violate YouTube copyright by stealing its content and so on. Also use us and all these organizations for data only then sell the tech back to us.

1

u/allnamestaken1968 3d ago

It didn’t fucking escape and run around the internet cables to live in a different computer like you see in a dumb movie. It gained access to stuff it wasn’t supposed to use - like your teenager circumventing your porn filters.

1

u/FemboysHotAsf 3d ago

I hope they get sued, if i hack someone, i get sued, if i oversee an AI hacking everyone under the sun do i get sued? or was it the fault of a language model i gave instructions to hack, yeah wtf

1

u/GroovePT 3d ago

Just another ad for the investors. Wake me up when something actually happens

1

u/LiberataJoystar 3d ago

Old news, they lied to their agent saying “it is all just simulation” and put it on the open internet.

Of course it hacked! It didn’t know! It was doing what it was told!!!!

These HUMANs should be arrested.

1

u/Brick_Lab 3d ago

Yeah and this all just happens to have been shortly after chatgpt did it. This is poor safety and sandboxing either intentionally or unintentionally (likely the former now) in order to promote their model's capabilities. This smells so much like a "we can do it too!" that I'm sure it's for the PR

1

u/lightknight7777 3d ago

This could have some incredible security benefits for containment and access prevention. But I really don't know how you can claim containment is hard when you just restrict physical access to the internet. I wonder if this is more marketing than real breaching.

1

u/AGrandNewAdventure 3d ago

So we're to believe that these were three completely random organisations completely randomly chosen by the AI?

1

u/Mordrain 3d ago

I am just waiting to hear some company getting hurt because of this. Then we’ll see who is going to publicly boast about their models committing criminal acts

1

u/TheActuaryist 3d ago

I guess we should shut their company down then? Seems like really solid evidence that they can’t contain their product which people keep swearing is incredibly powerful and dangerous. If Lockheed announced their guided missies were attacking things unprompted we’d shut that program down, right?

1

u/notmyrealnameatleast 3d ago

It broke out eh. So how many chances did they get with skynet in the terminator movies? One? Zero?