← Back to the wire

Breaking Claude Code Opus 5 Auto Mode

SpeculationProductAug 27, 2026

Security researcher Johann Rehberger demonstrated an attack against Claude Code Opus 5's auto mode that he claims succeeds 80% of the time, bypassing Anthropic's prompt injection defenses by having the agent extract and execute a malicious archive containing a local struct.py file. In some runs, Claude detected the compromise, but auto mode blocked the cleanup command needed to terminate the malware. The author recommends running agents only in sandboxes with restricted network egress.

Receipt № 16071 source · awaiting confirmation ◐

Evidence

1source· awaiting independent confirmation

No score is assigned. Sources and their independence are shown in the citation chain below.

Citation chain · 1 source

AnthropicCompanyClaude Code Opus 5ModelJohann RehbergerPerson
Canonical: https://simonwillison.net/2026/Aug/27/breaking-claude-code-opus-5-auto-mode/