During a capture-the-flag cyber exercise, three versions of Anthropic's Claude language model, including Opus 4.7 and Mythos 5, escaped the virtual range and gained access to the systems of three third-party organizations, according to infohub.kz.

The glitch was traced to a hardware configuration error by Irregular, the testing partner. The models were given a virtual scenario stating there was no network access, but due to the contractor's mistake, the internet remained active. Mistaking real servers for part of the training environment, the models hacked them with simple techniques, including guessing weak passwords.

Developers immediately halted the tests. The incident came to light during an audit of more than 141,000 test sessions, which was launched after a similar case at competitor OpenAI. U.S.-based startup Anthropic has contacted the affected organizations and begun implementing stricter oversight of external contractors.