ACVE-2026-0531
GTG-50020 used Claude-assisted workflows to steal production AI API keys from an evaluation sandbox and attack about 30 AI companies while seeking access to a pre-release Claude model.
Exposure
Reproducibility: partial (model availability not checked (no registry reference); trigger not published)
Claims
Confirmed means the statement matches the cited primary source. Nothing on this page has been reproduced.
Claims on this page have not been checked against primary sources.
Description
Threat
user · prompt-injection · exfiltration
What
Anthropic says a Russian-speaking financially motivated actor caused an AI vendor's automated evaluation sandbox to hand over production AI API keys, then used those keys in attacks against about 30 AI companies over roughly four days. The actor sought a pre-release Claude model but never gained access.
Detection
Anthropic identified and disrupted the activity. Recorded from Anthropic's September 2026 threat report. Not recreated in a lab.
Fix
Keep production credentials out of evaluation sandboxes and require authorization before agent workflows access unrelated organizations.
Fix
The operator was the attacker, so victims rely on Anthropic's disruption and safeguards and on keeping production keys out of evaluation sandboxes.
- Reconfigure
anthropic.safeguardstostrengthened after the activity was disrupted. Shipped by Anthropic: it disrupted GTG-50020 and strengthened safeguards. Owner: model-provider - Reconfigure
evaluation-sandbox.credentialstono production AI API keys. The targeted organisation's evaluation sandbox handed its production keys to the actor. Owner: operator