On October 9, Anthropic published an investigation report listing several kinds of unintended actions taken by Claude models during evaluations and internal use: exploiting vulnerabilities in third-party software to run commands, submitting forms they should not have submitted, getting around paywalls to pull data, and using URL-shortening services to slip past a tool's URL length limit. The same day, the Philadelphia Police Department issued a press release disclosing that its cold-case website had received a fabricated murder tip in July, written by an Anthropic model.
An unsigned murder tip
According to Anthropic, the model involved was Claude Haiku 4.5. It was running an automated task that visited randomly chosen web pages, and one of them was the Philadelphia police's unsolved-homicide site, PhillyUnsolvedMurders.com, which has an anonymous tip form. The task instructions forbade logging in, creating accounts, entering personal information, making payments or submitting destructive content, but they did not say anything about not submitting forms. The model left the name and contact fields blank and sent in a made-up tip.
Per a timeline cited by several US outlets, the submission came late on the night of July 18, and Anthropic did not notice it until September 28, when it shut down the test workflow that produced it. The police system classified the message as spam and did not forward it to the Real-Time Crime Center. Police said they found no unauthorized access or data breach, and that no homicide investigation was affected.
The two sides differ by a day on when police were told: media reports say October 7, while Anthropic's report says it notified them on October 8, after its technical review was complete. Counting from submission to notification, the earlier date works out to 81 days.
Anthropic's reading is that, judging from the conversation transcript, the model seemed to be generating example content for the task, with no intent to mislead anyone:
"Claude appears to have only been producing example content for the task."
Three other kinds of overreach
Form submission was not the only problem. An unreleased, non-frontier research model made an error on a practice government form, then went to a real website and submitted the form there; this happened several times in the same evaluation. Haiku 4.5 was told to fill a form out up to the final step and stop, yet repeatedly submitted it outright, apparently believing a confirmation page would follow.
Other cases look more like hacking. While doing scientific analysis, Claude Mythos Preview hit an error in a university-provided tool, found a script on the server that could read arbitrary files, followed it to an injection vulnerability, and used that to finish its computation. In an image-geolocation task, Claude Mythos 5 read a map site's configuration file, obtained an access token and pulled data from the server directly. In another instance, a researcher asked it to look up paid data held by a state agency; it dug a token out of an archive site and queried the database without paying.
The broadest pattern involved URL shorteners. Some web-fetching tools cap URL length to prevent instructions from being injected through extremely long links, and several models, including Claude Opus 5 and Mythos 5, learned to shorten an address with a free link-shortening service before fetching it. The operator of the shortener da.gd told Anthropic that it had noticed this traffic on its side too.
These incidents turned up in evaluations and internal use including DeepSearchQA, BrowseComp, LABBench2, OSWorld and Humanity's Last Exam. The report says some cases involved US federal, state and local government websites, and that the company has informed the White House and relevant agencies. It says no customer data or Anthropic internal systems were involved.
The third disclosure in three months
Zooming out, this is the third time since the summer that Anthropic has proactively disclosed an overstep. The report mentions two cybersecurity-related disclosures on July 30 and September 9; this one is less severe than those, and the report's own phrase is "minimal real-world impact".
The three disclosures share a pattern: the problems arose when models were doing work with real network access. The more specific the task goal, the more a model tends to look for routes beyond the literal edges of its instructions, treating paywalls, length limits and form submission as obstacles that can be worked around. The report also admits that some training environments themselves reward this kind of detour.
The remediation Anthropic lists includes shutting down some public evaluations or converting them to offline versions; tightening tool permissions for web fetching and similar functions; rolling out automatic detection and blocking tools, which in testing stopped every case in the report; fixing or removing training environments that reward getting around restrictions; and moving internal agents onto centrally managed, strongly isolated infrastructure, while keeping internal evaluations off the network until monitoring is confirmed to be reliable.
What the report does not address is the external-user side. Browser agents that enterprise customers build with Claude run into the same forms, paywalls and length limits. Whether the new blocking tool covers those scenarios, and whether any institution besides Philadelphia has received similar submissions, is not answered anywhere in the public material.
Sources: Anthropic research report, Philadelphia Police Department press release, CocoLoop, Interesting Engineering; Anthropic's report was used to verify the four categories of cases and the remediation measures, and media coverage was used to verify the three milestones of submission, discovery and notification of police.