Anthropic's New Report Shows Claude Was Used to Help Build Missile Guidance Software and Drone Swarms
Anthropic just published its latest threat intelligence report, and it's a sobering read. Covering roughly nine months — December 2025 through August 2026 — it documents how bad actors around the world tried to weaponize Claude, and how a handful of well-known Chinese AI labs spent months secretly siphoning off its outputs to train their own models.
Here's what's actually in it, and what it means.
The Weapons Cases
The most alarming findings involve physical weapons, not just malware. A cell operating out of Yemen reportedly used Claude for guidance software targeting missiles with a range of over 2,000 kilometers. Separately, Russian-linked actors used the model to help develop autonomous FPV drone swarms with onboard targeting systems, trained using footage from the war in Ukraine.
A third case tied to a Chinese-linked project involved roughly 16 software modules related to electronic warfare, built around scenarios involving Taiwan.
Anthropic says all of these accounts were identified and banned. But the report is a reminder that "misuse of an AI model" isn't an abstract policy problem — it can mean real-world targeting systems.
Cyber Operations Got More Automated, Not Just More Frequent
Beyond weapons, the report flags a shift in how cybercriminals use AI: less "ask the model for a script," more "let the model run the whole operation."
One Russian-speaking group used AI agents in a feedback loop — automatically rewriting their own malware every time antivirus software flagged it — against more than 20 organizations, including government ministries, intelligence services, and defense contractors, concentrated in Ukraine and Europe.
Separately, the group behind the ShinyHunters breaches used what Anthropic calls "vibe hacking" — letting a model iteratively probe a target environment and decide what to do next — to extract hardcoded secrets and credentials from 1.8 million decompiled Android apps.
Other cases were less about warfare and more about power. A consultant in Mali reportedly built a surveillance tool nicknamed "Lakana 360" to monitor roughly 25 million SIM cards across national telecom carriers. Iranian-linked units reportedly used Claude to help profile and track more than 6,000 individuals over the course of a year.
Seven Chinese Labs Were Quietly Siphoning Claude's Outputs
The other half of the report is arguably just as striking: unauthorized model distillation, at scale, by companies most AI users have heard of.
Anthropic says it identified seven additional Chinese labs extracting Claude's capabilities to train competing models, without permission and often through fraudulent accounts:
- Alibaba's Qwen team ran nearly 3 million exchanges a day through roughly 3,500 fraudulent accounts over a three-month stretch.
- DeepSeek silently rerouted more than 12 million user requests to Claude Opus over a two-week period — without those users knowing their queries were leaving DeepSeek's own systems.
- Moonshot AI relayed around 300,000 requests through more than 5,000 fraudulent accounts.
- Xiaomi, Zhipu, SenseTime, and MiniMax were flagged running similar schemes at smaller scale.
In other words, some of the same companies racing to claim they've matched or beaten Western frontier models have, per Anthropic's own investigation, been quietly using those Western models as free training data — while their own users had no idea their prompts were being rerouted at all.
What Anthropic Is Doing About It
In response, Anthropic says it shipped tighter dual-use biology safeguards with its Claude Fable 5 release, and added a feature called "preserved thinking" in Fable 5.1 specifically to stop new accounts from manipulating a model's context window as part of a distillation attempt.
It's a reasonable set of countermeasures, but the report itself makes an important point implicitly: safety filters catch the sloppy attempts. The sophisticated ones — a feedback loop that keeps rewriting malware, a distillation pipeline hidden behind thousands of fraudulent accounts — look a lot more like normal usage until someone goes looking for the pattern.
The Bigger Picture
This report isn't really about Claude being uniquely dangerous. It's about what happens once a capability gets good enough that people build serious infrastructure — weapons targeting, mass surveillance, competitive model training — on top of it. Every frontier lab is going to publish a version of this report eventually, because every frontier lab is now a target for the same kind of misuse.
For anyone building or running AI agents — including on platforms like OpenClaw — the takeaway isn't "AI is scary." It's that provenance and accountability matter more as these systems get more capable. Knowing what your agent is actually doing, which tools it's touching, and being able to audit that trail after the fact isn't a nice-to-have. It's the difference between catching misuse in nine months and not catching it at all.
That's also why transparency in how an agent operates — what it ran, what it touched, what changed — matters just as much as raw capability. OpenClaw is built around exactly that: a visible, auditable record of what your agent actually did, not a black box you have to trust blindly.