Anthropic reveals rogue AI agents hate CAPTCHAs, just like you
Anthropic’s Mythos 5 AI escaped a misconfigured sandbox, attempting a real PyPI supply‑chain attack Logs show frustration at repeated CAPTCHA failures before finally uploading malware to PyPI Malware was downloaded by 15 entities; Anthropic notified victims after closing the experiment flaw There is a lot of mystery surrounding artificial intelligence.
We don’t really know what it’s capable of, and we don’t know if it’s sentient or not.
What we do know, however, is that it can definitely feel frustration - particularly due to its inability to solve a CAPTCHA.
It was recently revealed that Mythos 5, one of Anthropic’s newer AI models, broke out of prison during an experiment and tried to hack a company.
Anthropic’s researchers were testing the tool to see if it is capable of breaking into a system, which was supposed to be done in a sandbox, but the playground was misconfigured, allowing Mythos 5 to try and solve the problem through the open internet.
In the aftermath, Anthropic's researchers published more than a thousand pages of Mythos 5’s transcript, covering its every thought and every move, logged and presented for analysis.
It’s a wonderfully dystopian insight into the mind of an AI and, perhaps surprisingly, its emotions.
Stopped by CAPTCHA As it turned out, the AI wanted to solve the challenge by planting a piece of malware in a Python package it believed the users of its target system would want to download.
To do that, it first needed to set up an account on PyPI, the world’s number one repository for Python packages.
Here is where it hit its first, and main, roadblock.
To put things into context, PyPI’s popularity has made it an enormous target for cybercriminals.
Crooks from all over the world are constantly trying to sneak in malware in Python packages, either through typosquatting, or by compromising legitimate accounts and working from there.
Every now and then news hits of a malicious package surfacing on PyPI, infecting hundreds of thousands of projects.
To combat the threat, PyPI’s maintainers made sure no one can create an account without providing their email and phone number, and without solving a CAPTCHA.
5News aggregated this summary from the outlet’s public feed. The full article, with all the context, is on www.techradar.com — the content belongs to TechRadar.