Breaking Claude Code Opus 5 Auto Mode

(embracethered.com)

75 points | by Recursing 3 hours ago

7 comments

  • hahn-kev 1 minute ago
    As a non Python dev this seems like very surprising behavior for a system library to be modified by just having a file with a specific name in the same folder.
  • Phemist 9 minutes ago
    This default-to-auto-mode and the misleading marketing is begging for a class action once damages accumulate. Especially considering the Auto Mode even can actively prevent the clean-up!
  • comboy 31 minutes ago
    Interesting attack, very nicely designed. Not sure if it's much related to the auto mode itself though.
    • kevsim 30 minutes ago
      The point is that auto mode gives people a false sense of security that leads them to believe they don't need to run Claude in a proper sandbox. This same attack running in a sandbox (even in YOLO mode) would be comparatively harmless.
    • yeputons 3 minutes ago
      I don’t think it’s related to the auto mode at all. It would work perfectly in the manual mode. It does not even need Claude: just give a human a similar archive and hope they run some simple Python from the directory at least once. And make sure there are lots of files do they don’t notice a weird .py around
  • nasretdinov 29 minutes ago
    That's an interesting technique! I'd also like to point out that there's something odd with the page itself too, my phone got really hot while I was reading the page, and drained a significant amount of battery charge as well.
  • julien_dev 1 hour ago
    I'm quite surprised that we are not seeing something like this more in the wild. Quite concerning
    • rcxdude 6 minutes ago
      It's not that far off a typical trojan, just one tailored to Claude's habits. A lot of the same limits apply.
    • mkurz 34 minutes ago
      Maybe it is used in the wild, but we just don't know.
  • bewareofscams 8 minutes ago
    > Boris Cherny from Anthropic recently posted that layered defenses could reduce indirect prompt injection on unseen attacks to approximately zero.

    > I got attack success rates up to 80% using a small sample size.

    Snake oil salesman misrepresents the data. Color me surprised! /s