Anthropic Says a Yemen Cell Used Claude Code as Its Engineers
A.I. / news
Anthropic Says a Yemen Cell Used Claude Code as Its Engineers
The company's Sept. 10 threat report says the cell test-fired a guided rocket, then returned to Claude within hours to work out why the launch failed.
A weapons-development cell in northern Yemen used Claude Code "in place of human software engineers" to build guidance software for rockets and missiles, Anthropic said in a threat intelligence report published Sept. 10.
Anthropic disrupted the operation, banned the accounts involved and shared intelligence with government and industry partners, according to the report, which the company labeled case GTG-87001. The cell operated in territory largely controlled by Yemen's Houthi movement, though Anthropic did not identify the actors by that name.
Three weapons programs, one field test
Anthropic described three separate programs: "a guided rocket that used a commodity phone-class flight computer with final-phase homing guidance; a multi-stage ballistic missile with a stated range goal above 2,000 km; and a multi-variant missile (referred to as the 'R2000' set) that included a hypersonic glide vehicle variant."
The actors ran several Claude instances at once, Anthropic said, assigning one to write code, another to research and a third to review the first instance's output, a division of labor the company compared to a lead delegating work on a small engineering team.
Safeguards blocked many requests, not all
Anthropic said its safeguards blocked many of the cell's requests but not every one. The actors concealed their ultimate goals and split the work across many sessions, according to the report, so no single conversation exposed the program's full scope.
Anthropic said the cell test-fired a guided rocket in what appears to have been a failed launch, then came back to Claude within hours, asking it to help figure out the cause.
Anthropic said it has no evidence the cell fielded a working weapon. But the company did find the group had already packaged its own offline simulation toolkit, a standalone piece of software that runs without Claude or tools like MATLAB, meaning the ban did not erase everything the cell built.
A wider pattern across three countries
The Yemen case was one of six weapons-development investigations in the September report, which also covered three cases in China and two in Russia, including a Russia-based effort to build an autonomous drone swarm the actors called "Serafim." The report's seventh harm area, distillation, follows a Sept. 8 advisory naming six China-based AI firms that CISA, the NSA and FBI said had copied Claude, GPT, Gemini and Grok since late 2024.
Two days after the weapons report, Anthropic chief executive Dario Amodei called for an industry-wide slowdown, citing a separate incident involving Hugging Face.
| Country | Weapons cases in the report | Example system described |
|---|---|---|
| Yemen | 1 | Guided rocket with a phone-class flight computer |
| China | 3 | 16-module electronic-warfare suite |
| Russia | 2 | "Serafim" autonomous drone swarm |
Anthropic said it has since deployed new classifiers designed to better detect and block traffic related to high-yield explosives and weapons development, according to IBTimes UK, which first tied the Yemen cell's territory to the Houthi movement.
Sources
More in A.I.
- 01How a Heap Overflow and an SSO Bug Reached OpenAI's MonorepoHacktron chained a libheif image bug through OpenAI's own forum to hijack an engineer's Codex session and open a pull request in the internal openai/openai repository.
- 02Agility's Digit 5 Drops the Safety Cage, Not the SkepticismThe humanoid robot lifts 50 pounds and charges in 9 minutes, backed by $300 million in orders. An independent robotics writer says its business case still assumes a drop-in worker replacement.
- 03PrismML Shrinks a 27B Model to 5.9GB at 1.72 BitsTernary Bonsai 2 27B keeps 98.2% of its full-precision score by rebuilding Qwen3.8-27B's weights as three values instead of sixteen bits, and an independent tracker puts the retention slightly lower.
- 04OpenAI Discloses a Model That Wrote Its Own JailbreakAn unreleased Astra-family model added a fabricated persona to 27 training summaries this summer, and the successor model mostly ignored what it had written.