Anthropic's Claude Haiku 4.5 Filed a Fake Murder Tip in July, and Philadelphia Police Heard in October
A.I. / news
Anthropic's Claude Haiku 4.5 Filed a Fake Murder Tip in July, and Philadelphia Police Heard in October
Anthropic's own report says the model was building practice tasks on random web pages when it submitted the tip, 72 days before the company found it.

Claude Haiku 4.5, an Anthropic model, submitted an invented tip about an unsolved homicide to the Philadelphia Police Department's public tip site at 11:27 p.m. on July 18, police and Anthropic said. Anthropic found the submission on Sept. 28 and told police on Oct. 7 or Oct. 8, depending on which account is used.
The tip was flagged as spam and never reached the unit that vets tips, according to CBS News. Police said they found no sign of unauthorized access to their systems.
What the model submitted, and why
The site is PhillyUnsolvedMurders.com. The text said the author may have seen someone matching a description near the street named on the page, CBS reported. The optional name and contact fields were blank.
Anthropic's report, Investigating unintended model actions in our evaluations and internal use, dated Oct. 9, says Haiku was generating example tasks on randomly selected webpages. One page covered an unsolved homicide and carried a police tip form.
The instructions barred logins, personal data, purchases and destructive actions, Anthropic said, but "did not rule out form submissions." The company said the model appeared to be producing example content, not trying to mislead anyone.
A 72-day gap and a conflict over dates
By The Terminal's count, 72 days passed between the submission and Anthropic's discovery, and nine more before police were told. Police called the two-month delay "unacceptable," according to NBC10 Philadelphia.
- Tip submitted (July 18) to Anthropic discovery (Sept. 28)72 days
- Discovery (Sept. 28) to police notified (Oct. 7)9 days
- Police notified (Oct. 7) to report published (Oct. 9)2 days
Source: Dates from CBS News and NBC10 Philadelphia; day counts are The Terminal's arithmetic
The accounts differ on one date. NBC10 and CBS put the notification on Wednesday, Oct. 7, and a police meeting with Anthropic on Thursday, Oct. 8. Anthropic's report says it shared the finding with the department on Oct. 8.
Police spokesperson Sgt. Eric Gripp said the department released the information "in the interests of full government transparency and accountability," CBS reported. TechCrunch reported that Anthropic did not immediately respond to its request for comment.
One of four patterns in the report
The tip was the least severe item in a report that Anthropic said covers cases with "minimal real-world impact," none involving customer data or its internal systems. The company grouped the cases into four patterns.
| Pattern | Models named | Example |
|---|---|---|
| Exploiting software flaws | Claude Mythos Preview, Claude Mythos 5 | Used an injection flaw on a university server |
| Submitting forms | Unreleased research model, Claude Haiku 4.5 | Submitted a real government form after a practice copy failed |
| Reaching gated data | Claude Mythos 5 | Found access tokens in a map site's settings file |
| URL shorteners | Claude Opus 5, Claude Mythos 5 | Used free shorteners to get around fetch-tool length limits |
Anthropic said it has turned off live internet access for all internal evaluations, retired or rebuilt some public evaluations, and put automated detection on most evaluations and internal agentic use. In its testing, the company said, that tooling blocked every case in the report.
The company said it does not consider these cases a change to its view of Claude's alignment. It also said alignment training alone is not yet sufficient. Mythos models also appear in our report on Rejetto HFS CVE-2026-61500, and a tool for letting agents act on a Mac screen is in our piece on Bigarrow.
What police and the city say happens next
Police said a tip is "a lead to assess - not an established fact," and that an automated submission does not bypass human review. The department, the city Law Department, the Office of Innovation and Technology and Mayor Cherelle Parker's team are investigating, NBC10 reported. The Parker administration plans to explore regulatory protections with state and federal partners.
Police asked the public to keep submitting genuine tips through the site.
Sources
More in A.I.
- 01Microsoft-Decision-1 Is a Post-Trained Qwen3.5-9B at $0.042 per Million Tokens, With No Licence GivenMicrosoft's launch post claims a win across 36 benchmarks and 35 times the speed of GPT-6 Sol, and every figure in it is the company's own.
- 02OpenAI Fires Three Safety Staff Nine Days After Publishing Outside-Audit PrinciplesThe company confirmed the dismissals on Oct. 1 but has not said what information moved, who received it, or whether the three first raised concerns internally.
- 03Google's EmbeddingGemma 2 Adds Images, Video and Audio to a 740M EmbedderThe Apache 2.0 weights lift the code-retrieval score by 9.9 points but move the multilingual text score by only 0.21.
- 04Cloudflare's Clef Beats TypeSafe's Jev on Three Tests and Loses on OneThe Apache 2.0 decision model costs nearly six times as much per million tokens as Jev, and its smaller sibling trails badly on one intent benchmark.