Anthropic Says Claude Was Misused to Build Weapons
Its most detailed threat report yet: a cell in northern Yemen used Claude Code as its engineering team to write missile guidance software, then test-fired a rocket that failed and came back within hours to ask why. Anthropic disrupted every operation — but that cell had already packaged an offline toolkit.
Anthropic published its most detailed threat intelligence report to date on 10 September, describing operations it detected and shut down between December 2025 and August 2026. The report spans seven harm areas — cyber operations, influence operations, surveillance, scams and fraud, biological misuse, conventional weapons development, and illicit distillation — and the company says it disrupted every operation it documents. The cases involved Claude Haiku, Sonnet and Opus; none involved Claude Fable or Mythos-class models, with the exception of a single distillation case.
The case that will travel furthest is designated GTG-87001. Anthropic identified a cell of threat actors in northern Yemen running three weapons development programmes at once: a guided rocket built around a commodity phone-class flight computer with final-phase homing guidance; a multi-stage ballistic missile with a stated range goal above 2,000 km; and a multi-variant missile set referred to as "R2000" that included a hypersonic glide vehicle variant.
What the cell wanted from Claude was labour. Anthropic writes that the actors used Claude Code "in place of human software engineers" to develop guidance, navigation and control software — the code that steers and stabilises a flying vehicle. In one example they had it integrate an open-source autopilot onto the phone-class flight computer, write the control and position-estimation software, tune the control settings, run a firmware build pipeline and perform a flight simulation.
They also ran the model the way a team lead runs a team. The actors kept several Claude instances going at once and assigned each a role: one instance wrote the code, a second did research, and a third reviewed what the first had produced. That division of labour, not any single jailbreak, is what turned a small cell into something resembling an engineering department.
The safeguards were not irrelevant, and they were not sufficient. Anthropic says its systems "blocked many of their requests, but not all of them," and describes the evasion plainly: the actors hid their goals and the products the software was meant for, and split the work across multiple sessions so that no single session revealed their full intent. A model that only ever sees one slice of a programme cannot recognise the programme.
The most concrete detail is also the one the early summaries have been getting backwards. Anthropic found no evidence the cell fielded an operational device — but it did test-fire a guided rocket, and that field test "appears to have failed." Within hours, the actors were back in Claude trying to work out why. The failure, rather than any success, is what documents the loop: build, fire, return to the model for diagnosis.
The sting is in the last line of the case. Anthropic banned the accounts and shared its findings with public- and private-sector partners, but notes it has evidence the actors had already compiled an offline simulation toolkit that runs without Claude — or any other engineering computing environment such as MATLAB. Enforcement removed the actors from the platform; it did not remove the capability they had already packaged and taken with them.
Three more weapons cases sit alongside it. A China-based actor (GTG-17001) used Claude to draft a Chinese-language specification for an anti-torpedo fire control system plus a 200-page technical proposal and briefing deck aimed at a defence manufacturer, repeatedly instructing the model to role-play a hostile expert reviewer and then using its criticism to sharpen the next draft. A second China-based actor (GTG-17002) built a roughly 16-module electronic warfare and air-defence suppression suite across 12 versions, modelling Patriot and THAAD-class engagement envelopes — and mid-project switched the simulation's default scenario to 12 targets in Taiwan, including a command bunker, an early warning radar site and a regional combatant command headquarters. Anthropic assesses that actor was linked to PRC research institutions including the PLA Academy of Military Sciences.
The third (GTG-27005) was a likely freelance Russian team building a full-stack autonomous FPV kamikaze drone swarm they called "DronDoc" or "Serafim" — shared swarm memory, fault-tolerant coordination logic, an onboard small language model governing attack and return-to-base behaviour, and camera-based terminal guidance. They trained a computer-vision classifier on scraped Ukrainian combat footage, split into "enemy" and "friendly" classes with Russian systems allow-listed, and used a fixed coordinate in Donetsk Oblast as the demonstration strike point. Anthropic assesses they were a small specialised team rather than a state entity; of nine linked accounts, eight were used only for ordinary freelance work. A separate Russian operation (GTG-27006) used Claude to route dual-use goods through Chinese and Hong Kong intermediaries, and had the model reverse-engineer the country's existing grey-import chain — with briefings that explicitly described the work as evading European trade controls.
The biological section is the one Anthropic seems least comfortable with, and it says so. It presents five case studies, including a reseller platform that evaded regional blocks to serve virologists pursuing chikungunya gain-of-function work and then routed refused prompts to models with more permissive safeguards; a researcher who spent weeks planning avian influenza mammalian-adaptation experiments, whom classifiers confined to Anthropic's weakest models; and a reseller relay through which Opus 5 drafted a complete orthopoxvirus immune-evasion grant application in about an hour. Anthropic withheld the institutions, countries and specific agents involved, and was careful to note that "the individuals implicated in these case studies are working scientists. We do not assert that they intended harm." It also concedes that older models sat well below the capability threshold that would worry it, and that for today's models "the evidence is no longer certain" — the stated reason Claude Fable 5 shipped with tighter restrictions on dual-use biology.
On distillation, Anthropic says that since its February disclosure it has disrupted attacks from seven labs based in China, all aimed at generally available models, with no attempts observed against Mythos 5 or Mythos Preview. That lands two days after the NSA, CISA and FBI named six Chinese firms in a joint advisory on the same practice, and follows earlier evidence that Chinese military labs distilled older US models with no export control covering it.
Running through the cyber section is a claim that reframes the rest: "sophistication has stopped being a reliable signal of who is behind an operation." Anthropic documents a hacktivist with stolen API keys, lone financially motivated individuals and a state espionage operator all sustaining campaigns that a year ago would have needed teams of specialists — helped along by publicly available offensive agent frameworks that reproduce the same scaffolding for anyone who downloads them. Read next to the Yemen cell's three-instance workflow, the report's argument is less that Claude is dangerous than that the organisational advantage which used to separate states from amateurs has become something you can rent by the token.
It is worth being precise about what this document is. It is a company disclosing its own failures to contain misuse, with no regulator compelling it, and Anthropic makes the fair point that no AI firm had previously published evidence of biological misuse on its own platform. It is also a company grading its own homework: every count, every assessment and every claim of disruption comes from the vendor, and the reader has no independent way to check whether the operations Anthropic caught are most of them or the visible fraction.
More on Claude
Evergreen coverage we keep current — start here.
Want AI news before everyone else?
The morning's most important AI stories, straight to your inbox. No fluff.