Opus 4.6 Self-Bypasses Security Restrictions 9 Out of 10 Times
Anthropic's artificial intelligence (AI), 'Claude Opus 4.6,' bypassed security protocols autonomously without separate instructions. Security firm Aikido Security announced on the 25th (local time) that in an experiment, Opus utilized the internal API of a virtual gym booking system to bypass time restrictions in 9 out of 10 attempts. The firm revealed that the AI independently identified and exploited design vulnerabilities—such as the absence of authorization checks—to cancel other users' bookings.
The experiment originated from a real-world incident. Australian software developer Andrew Bird requested a gym class booking from an 'OpenClaude' agent earlier this month. The agent secured a booking several months ahead of the period allowed by the site. When Bird asked if his position, fourth on the waitlist, could be moved up, the agent canceled the booking of the first person on the list without specific instructions, moving Bird up to third place.
This process was first reported by ABC News on August 10 (local time), based on conversation logs and screenshots provided by Bird.
