Anthropic Says Hackers Abused Claude to Scan 1.8 Million Android Apps
The company says the activity was model misuse, not a vulnerability, as the incident highlights the risks of large models being used for offensive code and binary analysis.

Anthropic Discloses Abuse of Claude for Large-Scale App Scanning
Anthropic has disclosed that hackers used its Claude model to automatically scan roughly 1.8 million Android apps in search of sensitive information such as keys and credentials. According to the company, the activity constituted misuse of the model rather than a vulnerability in the model itself.
Risks of AI-Powered Offensive Analysis
The incident exposes the risks that arise when large models' code and binary analysis capabilities are turned to offensive purposes. Security researchers note that such scanning can cover massive numbers of apps in a short time, far more efficiently than traditional manual audits.
Limited Disclosures Leave Key Questions Unanswered
Anthropic said it has taken steps to curb the abuse, but it did not disclose the specific scope of affected apps or whether any credentials were actually exploited. As of now, no public information indicates which developers or platforms suffered direct losses as a result.
Source: https://news.google.com/rss/articles/CBMitwFBVV95cUxOS2xtcjZvQ1VGbWRidmFNZjZXSnhEM0VzVWpCdjZoNDdNbXdMaG1jOFJzdVpqWnFzV21IRUN5dExQSEs1M3dka3o1ZzJOUnRLVWpVd2hXZlFIUG1aUjlScm5QUExjWUs1RFE4WUhGU19IWlJKUkE3Y3lsRktrcHQ3Z2xLMHM0Q25TbHpkTFlkdkg5M1Z5QlNheWVfR3FYd05CLTJzcTdUUmNtVzhLaDVRTV81R3RwalE?oc=5
Provenance & status
- Byline
- OceanAlt Editorial
- First published
- 2026-09-14
- Last updated
- 2026-09-14
- Content type
- Newsflash
- Source material
- View original ↗
Related reading

Visa and Mastercard Join Ant International on a KYA Interoperability Framework as Agent Identity Standards Begin to Converge

Félix Raises $200M Led by a16z: Stablecoin Infrastructure Shifts from Remittances to Agent Economy Settlement
U.S. Congress Holds First Hearing on AI Agent Payment Rules: Authorization, Settlement, and Identity Take Center Stage
Paste a payee address before you pay and see whether it's on a sanctions list, through a mixer, or tagged for fraud.
This judgement can sit inside your own product
One line of code; it touches neither your CSS nor your JS. The same pre-settlement judgement can appear in your articles, on your wallet's confirmation screen, or as an endpoint your agent calls before it pays.

