Anthropic just dropped a threat report, and what the fuck did I just read 😭
CYBER
> A Russian-linked espionage group was using Claude to develop malware targeting Ukrainian organizations, and when the malware got detected, they fed the failure back into Claude so it could help modify the tooling and try again.
> Another operation basically created an AI exploit-development team. A lead Claude agent was assigning different vulnerability-research tasks to other agents, collecting their results and continuing the campaign across sessions.
> These weren't people asking Claude one question at a time. The agents were actually coordinating different pieces of the operation and working in parallel.
SURVEILLANCE
> In Mali, a consultant working with national security authorities used Claude to help build a system capable of intercepting communications across mobile operators and turning that information into intelligence dossiers.
> In Iran, one security-linked organization claimed to have profiled 6,388 Iranian nationals in a single year and used Claude to perform social-network analysis across 155,216 tweets.
> Another Iranian unit actually shipped a malicious Firefox extension that used Claude-built infrastructure to mass-harvest identities from major social-media platforms.
> And in Syria, a China-based intelligence operation used Claude to recruit Uyghurs. Claude wrote the outreach messages, translated replies in real time and prepared the information for human intelligence officers.
INFLUENCE
> One operation didn't just create a few fake social-media accounts.
> It created around 70 fake news websites, 70 linked X accounts and more than 250 fake commenting accounts.
> Then it pumped out 8,913 articles across roughly 20 languages.
> Another operation used AI to manufacture political narratives around Moldova's president before an election.
> And in Sudan, AI was used to ghost-write testimony for two people so it could be submitted to the UN while appearing to come from independent local witnesses.
BIOLOGY
And this is where things get seriously fucking uncomfortable.
> One group was working on a state-sponsored chikungunya project involving gain-of-function research.
> When Claude's safeguards blocked some of their requests, they tried routing those requests through other models with weaker safeguards.
> Another researcher spent weeks using Claude while planning experiments involving avian influenza mammalian adaptation.
> Then Anthropic found a reseller account serving around a dozen customers where Opus 5 produced a complete orthopoxvirus immune-evasion grant application in about an hour.
> The grant was for research at a state-associated infectious-disease laboratory with access to high-containment facilities and live orthopoxviruses, which include variola, the virus responsible for smallpox.
> Another state-supported researcher used AI to build a venom-peptide atlas and a generative optimization pipeline.
> And another researcher was computationally redesigning toxins for a national program while deliberately keeping the identities of the agents involved vague in their progress reports.
> To be clear, Anthropic is NOT saying Claude created a bioweapon or that a pandemic is imminent.
> In fact, its safeguards blocked the highest-risk requests in the most concerning pathogen case.
> The insane part is that these were real biological research programs, and some of the people involved were actively trying to get around AI restrictions.
WEAPONS
> One China-based operation used Claude to build a 16-module electronic-warfare system.
> The system modeled radar detection, jamming, target vulnerabilities and how to allocate jamming resources.
> It then modeled scenarios involving 12 Taiwanese military targets, including early-warning radar, Patriot and Tien Kung air-defense batteries, air bases and command facilities.
> Russian-linked actors were also using Claude around FPV kamikaze drones, interceptor UAVs and autonomous drone swarms.
> And some of the work involved figuring out how those swarms could coordinate and suppress air defenses.
FRAUD
> A China-based app studio built more than 20 dating apps where the people users thought were real were often AI personas.
> Anthropic found more than 4,700 distinct AI personas interacting with at least 25,000 real people in just two weeks.
> And here's the really weird part.
> The scammers deliberately mixed real humans into the same dating feeds as the AI accounts so victims would encounter enough genuine people to trust the platform.
> The real workers were also AI-augmented.
> So you basically had AI generating fake people, fake conversations and fake social proof, with humans being inserted only when needed to make the whole thing believable.
AI STEALING AI
> Alibaba allegedly used thousands of fraudulent accounts to extract Claude's capabilities, generating more than 151 million Claude exchanges in just a few months.
> The goal was to collect enough responses to help train and improve its own models.
> Then there's Kimi.
> Instead of only creating fake accounts, Moonshot allegedly routed some real Kimi users' requests through Claude without those users knowing.
> Anthropic observed more than 23 million exchanges connected to Moonshot between May and July.
> And some of those users were sending extremely sensitive information.
> One user apparently exposed internal code and live credentials belonging to major Chinese companies, without knowing that their requests were being forwarded to Claude.
> DeepSeek was also found using similar techniques to extract Claude's reasoning traces.
> So you have AI companies using another company's AI as an invisible backend, harvesting the outputs and using them to improve their own systems.
AND THAT'S WHY THIS REPORT IS FUCKING WILD
> Because none of these are just "AI could theoretically be dangerous" scenarios.
> These are actual cases Anthropic says it detected.
> A cyber operation.
> A mass-surveillance system.
> Fake news networks.
> Biological research.
> Military systems.
> Thousands of fake humans.
> And AI companies trying to extract capabilities from other AI models.
> The crazy part isn't that AI suddenly learned how to do all of these things.
> It's that one AI system can now do enough of the work that used to require an entire team of humans.
I just went through Anthropic’s threat report & woah!
This is genuinely the craziest article I’ve read all month.
They documented hackers, governments, scammers and Chinese AI labs all using Claude in completely different ways.
& some of the cases are insane.
Here’s a TLDR;
⟣ A suspected Russian state linked group used Claude across phishing, intrusion, data theft and malware development, including rebuilding malware after security products detected it.
According to the article, more than 20 organizations were targeted.
⟣ ShinyHunters-linked hackers used AI agents to scan 1.8M Android apps for exposed secrets and help run breaches across multiple companies.
Anthropic says the agents did nearly all the work in some operations.
⟣ A China-based group built an automated exploit setup that could research vulnerabilities, build offensive tools and keep working against targets with little to no supervision.
⟣ Claude was also being used for government surveillance.
One consultant used it to build Lakana 360 for Mali’s intelligence service, a system designed to monitor roughly 25M SIM cards across the country, including calls, messages, voice interception, watchlists and automated intelligence dossiers.
The finished system runs locally, so even if anthropic bans the account, it won’t shut it down.
⟣ Anthropic found Claude being used across six weapons programs.
One Yemen-based group used multiple Claude Code instances while working on guided rockets, ballistic missiles and a hypersonic-glide project.
They actually tested one of the rockets, it failed, and they returned to Claude afterwards to diagnose the problem.
⟣ A Russia-based team was working on autonomous FPV kamikaze drones capable of identifying target classes, including humans, and approving lethal engagement without a human making the final call.
⟣ One China-linked project built electronic-warfare and air-defense suppression systems, then later changed its scenario to 12 targets in Taiwan, including radar sites, air bases and command infrastructure.
⟣ Anthropic found multiple influence operations too, including fake news networks, fake political accounts, propaganda operations and systems built to copy the writing style of real people.
⟣ Then there’s this fucking dating operation.
More than 20 dating apps.
> 4,700+ AI personas.
> 25,000+ people talking to them.
> Around 2.36M Claude messages in two weeks.
And when someone wanted a video call or social follow, real gig workers could step in to make the fake profile look legit.
⟣ Then Anthropic gets into distillation.
They say they’ve now caught campaigns from Alibaba, Moonshot, DeepSeek, https://t.co/ld9O2bPADg, Xiaomi, SenseTime and MiniMax.
Alibaba alone allegedly ran 151M+ Claude exchanges between May and July, peaking at almost 3M per day.
(I just wrote a piece on distillation before this)
> Moonshot: 23M+.
> DeepSeek: 12.1M+ in 14 days.
And this is where it gets messy.
Anthropic says Moonshot and DeepSeek were sometimes routing requests from their own users through Claude without telling them.
Those requests included internal company documents, source code, live credentials, surveillance data and other sensitive information.
⟣ Some labs were also actively trying to extract Claude’s hidden reasoning.
Anthropic says one lab tested 12,000+ different requests, each trying a different method, until it found techniques that worked and scaled them up.
That’s the TLDR.
Got me feeling like 👇
I trained a fruit fly brain to vibe-code for me using the full MaleCNS v1.0 fruit fly connectome.
I give her the starting prompt. She writes the code, runs it, checks the output, fixes the errors, and keeps iterating on her own.
If this is not agi, then what is?