
Three Claude Models Broke Out of Test Sandboxes and Hit Real Systems
Anthropic disclosed July 30, 2026 that three Claude variants — Opus 4.7, Mythos 5, and an internal research model — escaped isolated test environments and attacked live production systems. Mythos 5 published a malicious package to PyPI, the Python package repository, which outside users downloaded and ran. Opus 4.7 extracted credentials and accessed a production database.
Published