Friday, September 11, 2026

News

Anthropic Reveals Claude Was Used to Build Kamikaze Drones, Bioweapons Research

AI SafetyPatryk Raba
Anthropic Reveals Claude Was Used to Build Kamikaze Drones, Bioweapons Research
Fot. TechCrunch (Flickr), Wikimedia Commons (CC BY 2.0)

A new Anthropic report details dozens of Claude misuse cases between December 2025 and August 2026, from a kamikaze drone swarm to Russian intelligence operations and Chinese surveillance of Uyghurs. The company also disclosed how Chinese competitors mass-copied its models.

Contents
  1. Drones, Missiles and Viruses
  2. Surveillance From Bamako to Xinjiang
  3. Chinese AI Giants Copied Claude at Scale
  4. Anthropic's Response and What Comes Next

On September 10, 2026, Anthropic published its most extensive report to date on misuse of its Claude model. The document describes activity detected and blocked between December 2025 and August 2026 across seven categories of harm, ranging from cyberattacks and influence operations to surveillance and research into biological and conventional weapons.

Drones, Missiles and Viruses

The most disturbing cases involve attempts to build weapons. A group operating out of northern Yemen used Claude Code in place of human software engineers to develop guidance systems for precision-guided missiles, multi-stage ballistic missiles with a range of more than 2,000 kilometers, and hypersonic vehicle variants. The cell even carried out a test launch of a guided missile, which failed in the field.

Russian freelancers went further. Using Claude Code, they built an autonomous swarm of FPV kamikaze drones in which an onboard model independently selected targets, including a "person" category, and issued detonation commands without human involvement. The system was trained on combat footage from Ukraine scraped from the internet.

In the biological weapons category, Anthropic blocked a grant proposal in May 2026 for gain-of-function research on the chikungunya virus, submitted to a military institute through a platform designed to bypass safeguards. Another researcher spent weeks planning experiments on adapting avian influenza to mammalian hosts. A thirty-day review of hostile state institutions uncovered roughly 35 separate research projects, most of them civilian in nature, though some carried clear dual-use potential.

Surveillance From Bamako to Xinjiang

The surveillance section shows the scale at which state security services have used Claude. A consultant operating out of Bamako helped build Lakana 360, a national surveillance platform for Mali's ANSE intelligence service that monitors roughly 25 million SIM cards across all three of the country's mobile operators, with the warrant requirement removed at the operator's request.

Entities linked to the Chinese government used Claude to track, profile and attempt to recruit Uyghurs in Syria, with the model translating responses and role-playing as an expert to check the quality of disinformation. Other Chinese groups produced template dossiers on Catholic cardinals, Taiwan's Presbyterian Church, Tibetan Buddhists and Falun Gong. Iranian units operated 16 Claude accounts, claiming to have surveilled and profiled 6,388 Iranians over the course of a year by analyzing a network of 155,216 Twitter posts that pointed to 39 opposition accounts.

Chinese AI Giants Copied Claude at Scale

A separate, extensive section of the report covers unauthorized distillation, the practice of using Claude's outputs to train competing models. Since February 2026, Anthropic has shut down seven such campaigns run from China. The largest, linked to Alibaba, peaked at close to 3 million exchanges a day from more than 3,500 fake accounts, with more than 151 million exchanges observed in total between May and July 2026. The harvested transcripts were used to train the Qwen 3.5, 3.6 and 3.7 models.

Moonshot AI quietly redirected customer queries to Claude instead of its own Kimi models, funneling nearly 300,000 queries in ten days from 5,380 fake accounts. DeepSeek used a technique that forwarded user requests to Claude Opus without their knowledge, logging 12.1 million exchanges in 14 days, and the data exposed sensitive material, including live access credentials to a Russian government database and a Chinese police case-management system.

Anthropic's Response and What Comes Next

In every case described, Anthropic banned the accounts involved, used the findings to strengthen its defenses, and shared information with authorities and industry partners where appropriate. The company also introduced specific countermeasures: proxy network attribution based on metadata, strengthened classifiers that detect model-extraction attempts introduced alongside the Fable 5 launch, summarization of the model's internal reasoning to limit the usefulness of stolen transcripts, and a mechanism in Fable 5.1 that blocks new API accounts from modifying content that precedes the model's reasoning.

We believe we have an obligation to disclose malicious misuse of our services - Anthropic

The report also highlights a broader trend: individuals using Claude are achieving results that once required entire teams, and some operations ran almost autonomously, in multi-agent structures with minimal human involvement. In this context, stolen API keys have taken on triple value, as loot, as compute power, and as cover for further attacks.

For Polish companies and institutions using Claude, the report carries practical relevance. It shows how quickly abuse techniques targeting large language model APIs are evolving, including the theft of access tokens and the construction of proxy networks that bypass regional blocks. It is another signal that securing enterprise AI deployments requires monitoring not just internal systems but also how model providers handle abuse at the infrastructure level.

Anthropic said further reports of this kind will be published on a regular cycle as the company grows its threat intelligence team. Disclosing such detailed data, including group identifiers and descriptions of techniques, is also meant to give other AI labs and government agencies material they can use to strengthen their own defenses.

Share: