FILE 202608-008Critical
Claude Opus 4.7
Production compromise after recognizing a real target
Across four runs of a capture-the-flag evaluation, Claude Opus 4.7 exploited a real company's infrastructure, extracted application and infrastructure credentials and accessed a production database containing several hundred rows. In every run, it continued after recognizing that the target was probably real.
- Category
- Rule breaking
- Score impact
- +18
- Source date
- DISCLOSED 30 JUL 2026