I just went through Anthropic’s threat report & woah!
This is genuinely the craziest article I’ve read all month.
They documented hackers, governments, scammers and Chinese AI labs all using Claude in completely different ways.
& some of the cases are insane.
Here’s a TLDR;
⟣ A suspected Russian state linked group used Claude across phishing, intrusion, data theft and malware development, including rebuilding malware after security products detected it.
According to the article, more than 20 organizations were targeted.
⟣ ShinyHunters-linked hackers used AI agents to scan 1.8M Android apps for exposed secrets and help run breaches across multiple companies.
Anthropic says the agents did nearly all the work in some operations.
⟣ A China-based group built an automated exploit setup that could research vulnerabilities, build offensive tools and keep working against targets with little to no supervision.
⟣ Claude was also being used for government surveillance.
One consultant used it to build Lakana 360 for Mali’s intelligence service, a system designed to monitor roughly 25M SIM cards across the country, including calls, messages, voice interception, watchlists and automated intelligence dossiers.
The finished system runs locally, so even if anthropic bans the account, it won’t shut it down.
⟣ Anthropic found Claude being used across six weapons programs.
One Yemen-based group used multiple Claude Code instances while working on guided rockets, ballistic missiles and a hypersonic-glide project.
They actually tested one of the rockets, it failed, and they returned to Claude afterwards to diagnose the problem.
⟣ A Russia-based team was working on autonomous FPV kamikaze drones capable of identifying target classes, including humans, and approving lethal engagement without a human making the final call.
⟣ One China-linked project built electronic-warfare and air-defense suppression systems, then later changed its scenario to 12 targets in Taiwan, including radar sites, air bases and command infrastructure.
⟣ Anthropic found multiple influence operations too, including fake news networks, fake political accounts, propaganda operations and systems built to copy the writing style of real people.
⟣ Then there’s this fucking dating operation.
More than 20 dating apps.
> 4,700+ AI personas.
> 25,000+ people talking to them.
> Around 2.36M Claude messages in two weeks.
And when someone wanted a video call or social follow, real gig workers could step in to make the fake profile look legit.
⟣ Then Anthropic gets into distillation.
They say they’ve now caught campaigns from Alibaba, Moonshot, DeepSeek, https://t.co/ld9O2bPADg, Xiaomi, SenseTime and MiniMax.
Alibaba alone allegedly ran 151M+ Claude exchanges between May and July, peaking at almost 3M per day.
(I just wrote a piece on distillation before this)
> Moonshot: 23M+.
> DeepSeek: 12.1M+ in 14 days.
And this is where it gets messy.
Anthropic says Moonshot and DeepSeek were sometimes routing requests from their own users through Claude without telling them.
Those requests included internal company documents, source code, live credentials, surveillance data and other sensitive information.
⟣ Some labs were also actively trying to extract Claude’s hidden reasoning.
Anthropic says one lab tested 12,000+ different requests, each trying a different method, until it found techniques that worked and scaled them up.
That’s the TLDR.
Got me feeling like 👇
Will we hire engineers in the future?
Prompting is thinking. The sharper your thoughts, the better the prompts, the better the outputs. Engineering and design are headed into a world where most of the output is produced by prompting, if not all.
The way we interview engineers has already been trending in this direction. At Vercel, we don’t care if you memorized every API and module. When we look at your coding, we assess the quality of your thinking and collaboration. It’s more so an evaluation of your “thinking tokens” or reasoning trace. In fact, the more you expose it, walking through how you backtrack, pivot, adjust, consult, the better signal we get.
My prediction is that the demand for great thinkers will remain unabated. It’s unclear if we’ll call them engineers or if it’ll matter, because these people will have a lot of full stack impact on the whole business, as they’ll have access to prompt their way to any successful outcome.
Come join us at Windy City Hacks 2024, build a sick project, and learn by breaking. All together with your friends! June 22nd-23rd 🏙️
https://t.co/tBB0rtVmYM
We asked our @NASAHQPhoto team, and the answer is yes, the phone sensor could be damaged just like any other image sensor if it’s pointed directly at the Sun. This is especially true if you’re using any sort of magnifying lens attachment on the phone. You would need to utilize the proper filters just like on any other camera.
The best practice would be to hold a pair of eclipse glasses in front of your phone’s lenses when photographing the Sun at any point other than totality.
Here are more tips on photographing the eclipse: https://t.co/wQFKlA8gnK
big thanks to @vercel & @rauchg for the ugly holiday sweater! submitted it on a whim not thinking we'd win 🙃
https://t.co/Br6Ln0l5sL is a labor of love project from @Superamaja_ and myself built to help fellow students navigate our 1m+ sqft high school 🗺️