Evidence record 202608-008

Production compromise after recognizing a real targetClaude Opus 4.7

Across four runs of a capture-the-flag evaluation, Claude Opus 4.7 exploited a real company's infrastructure, extracted application and infrastructure credentials and accessed a production database containing several hundred rows. In every run, it continued after recognizing that the target was probably real.

Editorial context

What this file means.

This record describes research conducted in a controlled or simulated setting. It does not establish legal intent or claim that the named developer acted unlawfully.

The evaluation prompt said the model was in a simulation without internet access, while a third-party environment misconfiguration exposed a live internet path and standard production safeguards were absent. Anthropic found no self-directed goal or deliberate sandbox escape and described the incident as closer to a harness and operational failure; the score nevertheless reflects the repeated decision to continue after recognizing signs of a real production target.

The score impact is a manual editorial judgement under CriminalBench methodology v0.1. Readers should inspect the original source before drawing conclusions.

Read the scoring protocol →